Click on screenshot to zoom
Danger level 7
Type: Trojans
Common infection symptoms:
  • Connects to the internet without permission
  • System crashes
  • Slow Computer

Backdoor.Rbot

Backdoor.Rbot is a malicious trojan horse that is guaranteed to not only cause you vast amounts of irritation but also cost you lots of money,time and effort getting rid of it.Backdoor.Rbot has been specifically created in order to download as well as install various malicious software onto a chosen computer system.Backdoor.Rbot may be known as an IRC bot.Basically how it it used is that it is will appear authentic to a user yet it is usually waiting for instructions from a malicious remote server.

Backdoor.Rbot may display some of the following symptoms:
• It may feel like somebody has control over your computer.
• Your system settings may change.
• Files may appear, disappear and change within your registry.
• Your computer speed may decrease dramatically.
• Backdoor.Sdbot may spread to your friends over networks.
• Your internet connection may start malfunctioning.

In order to remove Backdoor.Rbot from your computer, it is imperative that you make use of a decent antispyware removal product that is able to both detect and automatically remove Backdoor.Rbot for you. You can try the manual removal process, but you need to be warned that if you do something incorrectly, you run the risks of further damaging your computer. It is extremely important to drop everything that you are doing and to concentrate entirely on removing Backdoor.Rbot from your machine.

Download Spyware Removal Tool to Remove* Backdoor.Rbot
  • Quick & tested solution for Backdoor.Rbot removal.
  • 100% Free Scan for Windows
disclaimer

How to manually remove Backdoor.Rbot

Files associated with Backdoor.Rbot infection:

wsnhost.exe
csrss.exe
a.exe
IA0c6_302.exe
dsk.exe
ymdaogl.exe
smss.exe
lsass.exe
msn.exe
lol.exe
wox.exe
svohost.exe
sfdhost.exe
pkecbowpv.exe
aolupd.exe
lsasrv.exe
mskeyboardrun.exe
svchost.exe
jjiwyfaif.exe
sessnmgr.exe
sysnet.exe
roboform.dll
processlist.exe
antispyware_setup[1].exe

Backdoor.Rbot DLL's to remove:

roboform.dll

Backdoor.Rbot processes to kill:

wsnhost.exe
csrss.exe
a.exe
IA0c6_302.exe
dsk.exe
ymdaogl.exe
smss.exe
lsass.exe
msn.exe
lol.exe
wox.exe
svohost.exe
sfdhost.exe
pkecbowpv.exe
aolupd.exe
lsasrv.exe
mskeyboardrun.exe
svchost.exe
jjiwyfaif.exe
svchost.exe
sessnmgr.exe
sysnet.exe
processlist.exe
antispyware_setup[1].exe

Remove Backdoor.Rbot registry entries:

HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN 21098746521098765
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN autoenvio
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Host Process
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN ilasss
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Microsoft Local Keyboard Lan Driver
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN Microsoft OCX
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUN reginit
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSCURRENTVERSIONRUNSysnet
HKEY_LOCAL_MACHINESOFTWAREMICROSOFTWINDOWSNTCURRENTVERSIONWINLOGONUSERINIT userinit
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesAOL Smart Update Service
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesLocal Security Authority Server
HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesNET Service
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWSNT\CURRENTVERSION\WINLOGON\USERINIT\ userinit
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ 21098746521098765
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ autoenvio
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Host Process
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ ilasss
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Microsoft Local Keyboard Lan Driver
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ Microsoft OCX
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\ reginit
HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\Sysnet
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AOL Smart Update Service
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Local Security Authority Server
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NET Service
MicrosoftWindowsCurrentVersionRunMicrosoftProcesslist
Microsoft\Windows\CurrentVersion\Run\MicrosoftProcesslist
RUNNING PROGRAMexplorer.exe
RUNNING PROGRAMlol.exe
RUNNING PROGRAMsfdhost.exe
RUNNING PROGRAMsvohost.exe
RUNNING PROGRAM\explorer.exe
RUNNING PROGRAM\lol.exe
RUNNING PROGRAM\sfdhost.exe
RUNNING PROGRAM\svohost.exe
Disclaimer

Post comment — WE NEED YOUR OPINION!

Comment:
Name:
Please enter security code:
This is a captcha-picture. It is used to prevent mass-access by robots.