Resolve for W32/Apribot-C icon

Resolve for W32/Apribot-C

2.0/5 6
Certified 100% CLEAN Freeware   

A tool that removes W32/Apribot-C. #Virus protection  #Trojan remover  #Malware cleaner  #W32/Apribot-C  #Remove  #Remover  

Description

Free Download

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.

They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.

W32/Apribot-C is an IRC backdoor with spreading capability.

Each time the worm is run it tries to connect to a remote IRC server and join a specific channel. The backdoor component then runs in the background as a server process, listening for commands to execute. The infected computer can be used to perform several functions: W32/Apribot-C is an IRC backdoor with spreading capability.

Each time the worm is run it tries to connect to a remote IRC server and join a specific channel. The backdoor component then runs in the background as a server process, listening for commands to execute. The infected computer can be used to perform any of the following functions:

Proxy server (SOCKS4) FTP server SMTP server File system Manipulation Port scanner DDoS floods (TCP,UDP,SYN) Remote shell (RLOGIN) Key logger

When first run the worm copies itself to the Windows System folder under a randomly generated name. The copy may have some random data appended to it. In order for the copy to be run on startup, registry entries are created under random names in the following locations:

HKLMSoftwareMicrosoftWindowsCurrentVersionRun HKLMSoftwareMicrosoftWindowsCurrentVersionRunServices HKCUSoftwareMicrosoftWindowsCurrentVersionRun

The worm chooses from one or two of the following strings to form the filename:

SERV DISK STAT LOAD INI SCAN INIT SRV DSK CONF CFG MON DLL VXD CHK REG DRV WIN SYS Stat Load Scan Init Service Disk Config Monitor Check Reg Drive Win System

The following entry is also created: HKLMSOFTWAREMicrosoftWindows NTCurrentVersionWinlogon Shell = "Explorer.exe,[filename] -shell"

Many additional registry entries may be created, changed or deleted. In particular, many entries are created in the following registry locations:

HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer DisallowRun HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesSystem DisableRegistryTools HKLMSOFTWAREMicrosoftConnect

The following entries are set:

HKLMSYSTEMControlSet001ControlLsarestrictanonymous = 1 HKLMSYSTEMCurrentControlSetControlLsarestrictanonymous = 1

W32/Apribot-C may also attempt to disable debugging and firewall software.

The worm appends several lines to the HOSTS file, found in the driversetc subfolder of the Windows System folder. Each line consists of a randomly chosen IP address beginning with "127" and a web address. The worm appends this data in order to prevent access to a number of anti-virus and Microsoft web sites.

W32/Apribot-C can be removed from Windows computers automatically with the following Resolve tools:

APRIBGUI is a disinfector for standalone Windows computers. To use it you have to do the following: ■ Open APRIBGUI.com file from your desktop after downloading it. ■ Click on the Start Scan Button. ■ Wait for the process to complete.

APRIBSFX.EXE is a self-extracting archive containing APRIBCLI, a Resolve command line disinfector for use on Windows networks.

Resolve for W32/Apribot-C 1.06

add to watchlist add to download basket send us an update REPORT
  runs on:
Windows All
  file size:
76 KB
  filename:
apribgui.com
  3 screenshots:
Resolve for W32/Apribot-C - screenshot #1Resolve for W32/Apribot-C - screenshot #2Resolve for W32/Apribot-C - screenshot #3
  main category:
Antivirus
  developer:
  visit homepage

calibre

Effortlessly keep your e-book library thoroughly organized with the help of the numerous features offered by this efficient and capable manager
calibre

Windows Sandbox Launcher

Set up the Windows Sandbox parameters to your specific requirements, with this dedicated launcher that features advanced parametrization
Windows Sandbox Launcher

Zoom Client

The official desktop client for Zoom, the popular video conferencing and collaboration tool used by millions of people worldwide
Zoom Client

IrfanView

With support for a long list of plugins, this minimalistic utility helps you view images, as well as edit and convert them using a built-in batch mode
IrfanView

Bitdefender Antivirus Free

Feather-light and free antivirus solution from renowned developer that keeps the PC protected at all times from malware without requiring user configuration
Bitdefender Antivirus Free

Microsoft Teams

Effortlessly chat, collaborate on projects, and transfer files within a business-like environment by employing this Microsoft-vetted application
Microsoft Teams

ShareX

Capture your screen, create GIFs, and record videos through this versatile solution that includes various other amenities: an OCR scanner, image uploader, URL shortener, and much more
ShareX

4k Video Downloader

Export your favorite YouTube videos and playlists with this intuitive, lightweight program, built to facilitate downloading clips from the popular website
4k Video Downloader

paint.net

Packed with an array of options and an intuitive interface, this application enables you to create professional-looking photographs
paint.net

7-Zip

An intuitive application with a very good compression ratio that can help you not only create and extract archives, but also test them for errors
7-Zip

% discount
4k Video Downloader
  • 4k Video Downloader
  • paint.net
  • 7-Zip
  • calibre
  • Windows Sandbox Launcher
  • Zoom Client
  • IrfanView
  • Bitdefender Antivirus Free
  • Microsoft Teams
  • ShareX
essentials


User Comments
This enables Disqus, Inc. to process some of your data. Disqus privacy policy