Alias
-
Backdoor.Rbot.gen
-
W32/Sdbot.worm.gen.g
-
W32.Spybot.Worm
Características
-
Permite que terceras personas accedan al equipo
-
Roba información
-
Utiliza un motor de correo electrónico propio
-
Reduce la seguridad del sistema
-
Registra pulsaciones en el teclado
-
Se instala en el registro
Sistemas operativos afectados
Instrucciones de recuperación:
Siga las instrucciones para eliminar gusanos.
You will also need to edit the following registry entries, if present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Updates = systemc32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Updates = systemc32.exe
and delete them if they exist.
Each user has a registry area named HKEY_USERS\[code number indicating user]\. For each user locate the entry:
HKCU\[code number]\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Updates = systemc32.exe
and delete it if it exists.
Close the registry editor.
- Download and install the Microsoft patches mentioned. On standalone computers, update with all relevant security patches from Windows update.
- Check your administrator passwords and review network security.