How to remove the W32/Codbot-E Worm (wzdsvc.exe)
What this program does:
This is a network worm that spreads via unsecure network shares and for certain vulnerabilities found in Windows.
Tools Needed for this fix: Related Tutorials: Symptoms in a HijackThis Log (Maybe different entries but will contain the same domains and hostnames):
O23 - Service: Wireless Zero Daemon - Unknown - C:\WINDOWS\system32\wzdsvc.exe
Removal Instructions:
- Download HijackThis from the above link and extract it to c:\hijackthis.
- Print out these instructions.
- Close Internet Explorer and keep it closed throughout the entire removal
process.
- Navigate to the c:\hijackthis directory and double-click on HijackThis
- When the program starts, double-click on the HijackThis icon and then click
on the Scan button.
- Put a checkmark next to the following entries if they exist:
O23 - Service: Wireless Zero Daemon - Unknown - C:\WINDOWS\system32\wzdsvc.exe
- Then click the Fix button.
- HijackThis will tell you that you need to reboot your computer in order
to finish this task. Allow your computer to reboot.
- When your computer is restarted, delete the following file:
c:\windows\system32\wzdsvc.exe
This is a self-help guide. Use at your own risk.
BleepingComputer.com can not be held responsible for problems that may occur by using this information. If you would like help with any of these fixes, you can post a HijackThis log in our HijackThis Logs and Analysis forum.
If you have any questions about this self-help guide then please post those questions in our AntiVirus, Firewall and Privacy Products and Protection Methods forum and someone will help you.