winlogon32.bat - Dangerous
winlogon32.bat
Manual removal instructions:
Antivirus Report of winlogon32.bat:
winlogon32.bat
BAT.Igador is a batch script worm that spreads using Internet Relay Chat (IRC).
Attempts to end the following processes using the TSKILL utility:
taskmgr; msconfig; ICQ; ICQLite; NISUM; NISSERV; guard; zonealarm; outpost; ad-aware; nmain
Modifies or creates the following files, so that a copy of the worm is sent to other MIRC users:
%ProgramFiles%\mIRC\mirc.ini
%ProgramFiles%\mIRC\eventz.ini
Modifies the %Windir%\Win.ini file so that the worm will run when Windows starts.
Overwrites all .pif files in the %Windir%\System32 folder with a copy of itself.
Deletes all files that have the extension .mp3 in the current folder.
Automatic removal: Use RegRun Startup Optimizer.
winlogon32.bat | Malware |
winlogon32.bat | Dangerous |
winlogon32.bat | High Risk |
Attempts to end the following processes using the TSKILL utility:
taskmgr; msconfig; ICQ; ICQLite; NISUM; NISSERV; guard; zonealarm; outpost; ad-aware; nmain
Modifies or creates the following files, so that a copy of the worm is sent to other MIRC users:
%ProgramFiles%\mIRC\mirc.ini
%ProgramFiles%\mIRC\eventz.ini
Modifies the %Windir%\Win.ini file so that the worm will run when Windows starts.
Overwrites all .pif files in the %Windir%\System32 folder with a copy of itself.
Deletes all files that have the extension .mp3 in the current folder.
Automatic removal: Use RegRun Startup Optimizer.
Dmitry Sokolov:
I created UnHackMe in 2006 to fix the problem that antivioruses did not fix: detecting rootkits.
Since that time I work every day to fix the issues that antiviruses cannot.
If your antivirus have not helped you solve the problem, you should try UnHackMe.
We are a small company and you can ask me directly, if you have any questions.