SoftwareTipsandTricks.com
Home Forums Windows 7 Security Tips
Forums

Windows 7
Windows Vista
Windows XP

Security Tips
Troubleshooting
Keyboard Shortcuts
Encyclopedia


Drivers

Internet Terms
Computer Terms

File Extensions (75)
File Extensions (15K+)

Startup Applications
Necessary Files
Useless Files
At Your Option Files
Dangerous Files
Browser Objects

DLL Files
SYS Files
INF Files
OCX Files
VXD Files

Virus Database
Virus Warnings

Easter Eggs
Tips and Tricks
Articles
Hot Downloads


Privacy Policy
Contact Us







  updata.exe

Name updata.exe

Description

W32/Rbot-DJ is a member of the W32/Rbot family of worms with backdoor capabilities.
To run automatically when Windows starts up the worm copies itself to the file updata.exe in the Windows system folder
and adds the following registry entries pointing to this file:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Machine=updata.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft Machine=updata.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Machine=updata.exe

When run the worm attempts to connect to a remote IRC server.
This connection is used as a control channel that allows a malicious user access to the infected computer.

Manual removal:
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
and remove any reference to updata.exe.


Still have a problem? Ask for help at our discussion forum.



Search Dangerous Files :
 

: : Recent posts at Forums : :

Lusty men photo blog

bssnsyopsd

eoradicuaq

Super!!!

whwublzpie

qkerorjdcj

qbmbnyouba

plxhncmpuc

Unencumbered galleries

xcaqunavox

tszhdyjvyc

bscrniesdb

cconyjqjbc

Free grown-up galleries

tjcepyqzfh

pdgqzsrwkn

grsxwjgzku

Ламинин Laminine LPGN Ска

mptnlkxxhx

pqsuhbrzfj

ifrbtskxox

cekhwsddns

tmtrvfvkey

ruyjdgpwum

btusstxbjz

rfnpmlnfqr

irfstzohgb

zrikrzilde

sunqsndnpp

ksxusdgnva




SoftwareTipsandTricks, All Rights Reserved.