| Backdoor.Win32.Rbot.gen removal| Spyware Rbot.gen Information |
|---|
Name: Backdoor.Win32.Rbot.gen Category: Backdoor Date: 2005-04-09 Dangerous: Yes | Backdoor.Win32.Rbot.gen is Backdoor - spyware. You should remove it from your system as soon as possible. >> Delete Backdoor.Win32.Rbot.gen automatically - Download Spyware Doctor
| Backdoor.Win32.Rbot.gen Removal Instructions |
|---|
Kill the following processes ~5c.exe, 50cent.exe, nav32sp.exe, prot.exe, lsasss.exe | Unregister the following DLLs and reboot oi00r1z.dll.
| Delete these registry entries HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\system32 HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices\system32
| Remove the following files 50cent.exe, files.ini, nav32sp.exe, oi00r1z.dll, prot.exe, ~5c.exe. lsasss.exe in Windows\system32\
|
Bookmark Backdoor.Win32.Rbot.gen page
| Visitor Comments on Backdoor.Win32.Rbot.gen |
|---|
2006-11-24 23:27:51, avionboy: when i try to delete lsass.exe i get an ACESS DENIED message so it might be difficult to get around this, and on hte TASK MANAGER when I try to stop the lsass process it does not allow me to end it saying it is a CRITICAL SYSTEM PROCESS. | 2007-04-04 23:52:23, AndyMo: Its lsasss.exe VS lsass.exe (extra 's'), the latter one is a needed windows component and so you will not be able to kill it. | 2007-12-16 11:14:51, Jacca: like most backdoors the Process melt and Exe name after init is changable by the Cracker |
|