updata.exe - Dangerous

updata.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

updata.exe
W32/Rbot-DJ is a member of the W32/Rbot family of worms with backdoor capabilities.
To run automatically when Windows starts up the worm copies itself to the file updata.exe in the Windows system folder
and adds the following registry entries pointing to this file:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Machine=updata.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft Machine=updata.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Machine=updata.exe

When run the worm attempts to connect to a remote IRC server.
This connection is used as a control channel that allows a malicious user access to the infected computer.

Manual removal:
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
and remove any reference to updata.exe.

Remove updata.exe now!