We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Backdoor:Win32/IRCbot!8497
Aliases: Win32/Checkout.A (CA) Backdoor.Win32.IRCBot.aaq (Kaspersky) W32/Checkout (McAfee) Backdoor:Win32/IRCbot!751D (Microsoft) W32/IRCBot-WB (Sophos) VIPRE.Suspicious (Sunbelt Software) W32.Mubla (Symantec)
Summary
-
Disconnect from the Internet.
-
Delete the Trojan registry entries.
-
Restart the computer.
-
Delete the Trojan files from your computer.
-
Take steps to prevent re-infection.
Disconnect from the Internet
Delete the Trojan registry entry
-
On the Start menu, click Run.
-
Type regedit and click OK.
-
In the left pane, navigate to the key:
HKEY_CLASSES_ROOT\CLSID\ -
Click Edit and click Find.
-
Type syshosts.dll and press Enter.
-
In the right pane, right-click the related CLSID value such as {5A2670F7-6E8B-4A4D-A71F-9B71A86EEFD6}.
-
Click Delete and click Yes to delete the value.
-
In the left pane, navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ -
In the right pane, right-click the following value, if it exists: syshosts
-
Click Delete and click Yes to delete the value.
-
Close the Registry Editor.
Restart the computer
-
On the Start menu, click Shut Down.
-
Select Restart from the drop-down list and click OK.
Delete the Trojan files from your computer
-
Click Start, and click Run.
-
In the Open field, type %WinDir%.
-
Click OK.
-
Click View, and Details.
-
Click Name to sort files by name.
-
Delete photos.zip from the Windows folder.
-
In the Address field, type %WinDir%\System32, and press Enter.
-
Click View, and Details.
-
Click Name to sort files by name.
-
Delete syshosts.dll from the Windows system folder.
-
On the Desktop, right-click the Recycle Bin and click Empty Recycle Bin.
-
Click Yes to confirm the deletion.