Softpedia
 

WINDOWS CATEGORIES:



GLOBAL PAGES >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
WEEK'S BEST
  • Sticky Password FR...
  • Parallels Workstat...
  • ESET NOD32 Antivir...
  • BitDefender Total ...
  • WinPatrol 24.6.201...
  • PerfectDisk Free D...
  • Adobe Photoshop CS...
  • PerfectDisk Profes...
  • Windows 8 Consumer...
  • Atlantis Word Proc...
  • Home > Windows > Antivirus > Removal Tools
     Report malware

    Resolve for W32/Apribot-C 1.06

    download button

    Downloads: 1,615  Tell us about an update
    User Rating:
    Rated by:
    Good (3.0/5)
    13 user(s)
    Developer:

    License / Price:

    Size / OS:

    Last Updated:

    Category:

    Freeware / $0
    76 KB / Windows All

    C: \ Antivirus \ Removal Tools

     Read user reviews (0)  Send to friend   Follow (0 users)

    Resolve for W32/Apribot-C description

    A tool that removes W32/Apribot-C

    Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.

    They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.

    W32/Apribot-C is an IRC backdoor with spreading capability.

    Each time the worm is run it tries to connect to a remote IRC server and join a specific channel. The backdoor component then runs in the background as a server process, listening for commands to execute. The infected computer can be used to perform several functions: W32/Apribot-C is an IRC backdoor with spreading capability.

    Each time the worm is run it tries to connect to a remote IRC server and join a specific channel. The backdoor component then runs in the background as a server process, listening for commands to execute. The infected computer can be used to perform any of the following functions:

    Proxy server (SOCKS4)
    FTP server
    SMTP server
    File system Manipulation
    Port scanner
    DDoS floods (TCP,UDP,SYN)
    Remote shell (RLOGIN)
    Key logger

    When first run the worm copies itself to the Windows System folder under a randomly generated name. The copy may have some random data appended to it. In order for the copy to be run on startup, registry entries are created under random names in the following locations:

    HKLMSoftwareMicrosoftWindowsCurrentVersionRun
    HKLMSoftwareMicrosoftWindowsCurrentVersionRunServices
    HKCUSoftwareMicrosoftWindowsCurrentVersionRun

    The worm chooses from one or two of the following strings to form the filename:

    SERV
    DISK
    STAT
    LOAD
    INI
    SCAN
    INIT
    SRV
    DSK
    CONF
    CFG
    MON
    DLL
    VXD
    CHK
    REG
    DRV
    WIN
    SYS
    Stat
    Load
    Scan
    Init
    Service
    Disk
    Config
    Monitor
    Check
    Reg
    Drive
    Win
    System

    The following entry is also created:
    HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon
    Shell = "Explorer.exe,[filename] -shell"

    Many additional registry entries may be created, changed or deleted. In particular, many entries are created in the following registry locations:

    HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer
    DisallowRun
    HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem
    DisableRegistryTools
    HKLMSOFTWAREMicrosoftConnect

    The following entries are set:

    HKLMSYSTEMControlSet001ControlLsarestrictanonymous = 1
    HKLMSYSTEMCurrentControlSetControlLsarestrictanonymous = 1

    W32/Apribot-C may also attempt to disable debugging and firewall software.

    The worm appends several lines to the HOSTS file, found in the driversetc subfolder of the Windows System folder. Each line consists of a randomly chosen IP address beginning with "127" and a web address. The worm appends this data in order to prevent access to a number of anti-virus and Microsoft web sites.

    W32/Apribot-C can be removed from Windows computers automatically with the following Resolve tools:

    Windows disinfector
    APRIBGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
    · Open APRIBGUI.com file from your desktop after downloading it.
    · Click on the Start Scan Button.
    · Wait for the process to complete.

    Command line disinfector
    APRIBSFX.EXE is a self-extracting archive containing APRIBCLI, a Resolve command line disinfector for use on Windows networks.

     Softpedia guarantees that Resolve for W32/Apribot-C 1.06 is 100% CLEAN, which means it does not contain any form of malware, including spyware, viruses, trojans and backdoors. [read more >]


    TAGS:

    virus protection | trojan remover | malware cleaner | W32/Apribot-C | remove | remover



    HTML code for linking to this page:


    Go to top

    WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

    SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM