It is very hard to fight Computer parasites alone in internet space. If you have a website we would be more than happy if you would help us to spread the knowledge about latest threats. You can help your
visitors to manage their Computer system manually without aditional expences. Knowledge is the power, we just need to spread it.
<br />
W32/Agobot-GS copies itself to network shares protected by weak passwords.<br />
<br />
When first run W32/Agobot-GS copies itself to the Windows system folder as winampa.exe. The worm will create the following registry entries to ensure it is<br />
run at system logon:<br />
<br />
HKLMSoftwareMicrosoftWindowsCurrentVersionRun<br />
Winampa = winampa.exe<br />
<br />
HKLMSoftwareMicrosoftWindowsCurrentVersionRunServices<br />
Winampa = winampa.exe<br />
<br />
On NT-based version of Windows the worm creates a new service named "Winampa" with the startup property set to automatic, so that the service starts automatically each time Windows is started.<br />
<br />
Each time W32/Agobot-GS is run it attempts to connect to a remote IRC server<br />
and join a specific channel. The worm then runs in the background allowing a remote intruder to issue commands which control the computer via IRC channels.<br />
<br />
W32/Agobot-GS will terminate and disable various anti-virus and security related programs.
I was viewing www.wrc.com and www.notam02.no/~hcholm/altlang/ at the time.
I have no Nullsoft products installed so I&#039;m assuming it&#039;s unwanted.
Post Comment: