SoftwareTipsandTricks.com
Home Forums Windows 7 Security Tips
Forums

Windows 7
Windows Vista
Windows XP

Security Tips
Troubleshooting
Keyboard Shortcuts
Encyclopedia


Drivers

Internet Terms
Computer Terms

File Extensions (75)
File Extensions (15K+)

Startup Applications
Necessary Files
Useless Files
At Your Option Files
Dangerous Files
Browser Objects

DLL Files
SYS Files
INF Files
OCX Files
VXD Files

Virus Database
Virus Warnings

Easter Eggs
Tips and Tricks
Articles
Hot Downloads


Privacy Policy
Contact Us







  NDRIVES32.EXE

Name NDRIVES32.EXE

Description

W32/Rbot-DK is a worm which attempts to spread to remote network shares.
It also contains backdoor Trojan functionality, allowing unauthorised remote access to the infected computer via IRC channels.
It spreads to network shares with weak passwords and via network security exploits as a result of the backdoor Trojan element.

Copies itself to the Windows system folder as NDRIVES32.EXE.
Creates entries at the following locations in the registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

W32/Rbot-DK may set the following registry entries:
HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = "N"
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = "1"

Also, may try to delete the C$, D$, E$, IPC$ and ADMIN$ network shares on the host computer.
Drops 3 files to the current folder called EXPIORER.EXE, ADMDLL.DLL and RADDRV.DLL, all of which appear to be legitimate remote server applications.

Use antivirus (also check How To Remove section)Startup Optimizer to remove this worm from startup.


Still have a problem? Ask for help at our discussion forum.



Search Dangerous Files :
 

: : Recent posts at Forums : :

Open grown-up galleries

ibuuxadrzr

mrcrmxadoh

wduxuykgav

thpympjsgd

xghpwqylbu

Mature galleries

sexrolloki

tvvwckxcaw

qsjkaxofig

pmbygaoxmm

uqmfxcprqb

pynfrmlmcz

toriguidhv

bziezmajei

tvdwunbnmy

Renewed install

zybzcfgvtk

qokoskvwiq

mkuzkpfzfv

aaklyyrklz

dphghovipu

phsfhptkad

iitsxgyljp

New site

flfbqlgtxi

srxhdwgmwe

ummxsnlvks

My new website

vqpdzkdxle




SoftwareTipsandTricks, All Rights Reserved.