This worm arrives by connecting affected removable drives to a system. It may be unknowingly downloaded by a user while visiting malicious websites.
It connects to certain URLs. It may do this to remotely inform a malicious user of its installation. It may also do this to download possibly malicious files onto the computer, which puts the computer at a greater risk of infection by other threats.
Arrival Details
This worm arrives by connecting affected removable drives to a system.
It may be unknowingly downloaded by a user while visiting malicious websites.
Installation
This worm drops the following component file(s):
- {removable drive}\recycler.lnk
It creates the following folders:
- {removable drive}\RECYCLER
Download Routine
This worm connects to the following malicious URLs:
- {BLOCKED}ney.biz
- {BLOCKED}ussy.info
- {BLOCKED}rebitch.com
Other Details
This worm connects to the following URL(s) to get the affected system's IP address:
- http://api.{BLOCKED}ia.com
Step 1
For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you to allow full scanning of your computer.
Step 2
Scan your computer with your live casino online product and note files detected as WORM_DORKBOT.BY
Step 3
Restart in Safe Mode
[ Learn More ]
[ back ]
To restart in Safe Mode:
• For Windows 2000 users
- Restart your computer.
- Press F8 when you see the Starting Windows bar at the bottom of the screen.
- Choose the Safe Mode option from the Windows Advanced Options menu then press Enter.
• For Windows XP users
- Restart your computer.
- Press F8 after the Power-On Self Test (POST) routine is done. If the Windows Advanced Options menu does not appear, try restarting then pressing F8 several times when the POST screen appears.
- Choose the Safe Mode option from the Windows Advanced Options menu then press Enter.
• For Windows Server 2003 users
- Restart your computer.
- Press F8 after Windows starts up. If the Windows Advanced Options menu does not appear, try restarting again and pressing F8 several times afterward.
- On the Windows Advanced Option menu, use the arrow keys to select Safe Mode then press Enter.
Step 4
Search and delete this file
[ Learn More ]
[ back ]
There may be some component files that are hidden. Please make sure you check the
Search Hidden Files and Folders checkbox in the More advanced options option to include all hidden files and folders in the search result. ?{removable drive}\recycler.lnk
To delete the malware/grayware/spyware file:
- Right-click Start then click Search... or Find..., depending on the version of Windows you are running.
- In the Named input box, type:
??{removable drive}\recycler.lnk
- In the Look In drop-down list, select My Computer, then press Enter.
- Once located, select the file then press SHIFT+DELETE to permanently delete the file.
Step 5
Search and delete this folder
[ Learn More ]
[ back ]
Please make sure you check the
Search Hidden Files and Folders checkbox in the More advanced options option to include all hidden folders in the search result.
{removable drive}\RECYCLER To delete the malware/grayware folder:
- Right-click Start then click Search... or Find..., depending on the version of Windows you are running.
- In the Named input box, type:
{removable drive}\RECYCLER
- In the Look In drop-down list, select My Computer, then press Enter.
- Once located, select the folder then press SHIFT+DELETE to permanently delete the folder.
Step 6
Search and delete the file detected as WORM_DORKBOT.BY
[ Learn More ]
[ back ]
To search and delete the malware/grayware file:
- Right-click Start then click Search... or Find..., depending on the version of Windows you are running.
- In the Named input box, type the name(s) of the file(s) detected earlier.
- In the Look In drop-down list, select My Computer, then press Enter.
- Once located, select the file then press SHIFT+DELETE to permanently delete the file.