Home > Malware Protection Center > Worm:Win32/Xtrat.C
Aug 06, 2015

How to remove Worm:Win32/Xtrat.C

Also known as BackDoor-FCDE!AB502CA6662A or W32.Spyrat , the virus Worm:Win32/Xtrat.C is possibly one of the most dangerous threats to infiltrate computer systems. It will enter the system through corrupted websites, spam emails attachments or external corrupted hard drives an immediately change its location thus spreading though the entire system and corrupting files and folders. The threat has been seen to connect to remote hosts like datac1.ddns.net using port 53 and mz3ro.no-ip.org using port 53 etc.

Worm:Win32/Xtrat.C removal is a matter of absolute necessity because as soon as it connects to the remote hosts it becomes capable of taking instructions from hackers and download other malware like Exploit:Win32/CplLnk.A or Trojan:Win32/Skeeyah.C!plock and others. It can also send the computer location to its author and upload information stolen from computers to the hackers. By logging the users keystroke data it will let the hackers steal banking passwords, credit card information, social security numbers and other important data.

How to detect it? It uses code injection to hide but if any of the files like:- %APPDATA % \roaming\microsoft\internet explorer\quick launch\launch internet explorer browser.lnk,

% TEMP % \322htr.exe,

%SystemRoot% \dlls\adsl.exe,

%TEMP% \710march.exe.exe ,

%TEMP% \ 710march.exe,

%TEMP% \dlshosts.exe,

%USERPROFILE% \documents\msdcsc\msdcsc.exe or %APPDATA%\roaming\Microsoft\windows\startmenu\programs\startup\a6bb84e8814fcaa6951c95e3faa45466.exe- are seen in any computer, then the system is infected and users need to remove Worm:Win32/Xtrat.C as soon as possible.

The threat creates corrupted registry entries in subkey - HKCU\Software\Microsoft\Windows\CurrentVersion\Run , sets the value a6bb84e8814fcaa6951c95e3faa4546 with the data c:\users\ administrator\appdata\local\temp\dlshosts.exe or sets the value HKCU with the data: %SystemRoot%\dlls\adsl.exe or in subkey- HKLM\Software\Microsoft\Active Setup\Installed Components\{VTVM542I-8743-2C38-TQKC-K3057FDG022L} sets the value StubPath with the data %SystemRoot%\dlls\adsl.exe and many others. And once it has done that it will start running as soon as the computer starts. Using an advanced Worm:Win32/Xtrat.C removal tool like Hit Malware not only guarantee that the malware and all other existing threats are removed, it will also make sure sure that the malware can never return and hackers can't get in tore computer in any way.

Click on the button below to download Worm:Win32/Xtrat.C removal tool - Hit Malware.

<-- VirTool:Win32/Obfuscator.AOJ | TrojanDownloader:Win32/Instondwn!rfn -->



Without any questions, you can get full refund within 60 days of purchase. The credit will appear on your account within 5 business days.


We protect your financial information and personal data with 256-bit SSL encryption.


PC knowledge articles help you fix, repair, optimize, protect and speed up your PC.