Remove Mogi. Description and removal instructions

 
Title: Mogi

Type: Worms
Severity scale:Mogi severity is 68  (68 / 100)
 
Mogi is an Internet worm, which spreads through file sharing networks using popular peer-to-peer applications including eDonkey2000, Kazaa, eMule, Limewire, Morpheus, BearShare and Gnucleus. It may also propagate via the ICQ network.

Once executed, Mogi silently installs itself to the system, hides dropped files with a rootkit, injects malicious code into running processes and runs a spreading routine. It creates infected files with meaningful names in shared directories of installed file sharing programs.

The worm's payload is comprised of several harmful functions. Mogi terminates running antiviruses, firewalls, security-related programs, associated update tools and processes of various other applications. It installs a rootkit in order to conceal its activity and presence in the system and performs Denial of Service attacks against predefined remote hosts.

Mogi automatically runs on every Windows startup.


Mogi properties:
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Mogi removal:

remover for Mogi

Mogi manual removal:

Kill processes:
ath.exe, bayloz.exe, bomba.exe, bonk.exe, dragon_naturallyspeaking_xp.exe, jolt2.exe, iexplore.exe, kod.exe, layer.exe, multi_password_cracker.exe, norton_2004_setup.exe, sin.exe, smurf.exe, suf.exe, syn.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\services=iexplore.exe
Delete files:
ath.exe, bayloz.exe, bomba.exe, bonk.exe, dragon_naturallyspeaking_xp.exe, jolt2.exe, iexplore.exe, kod.exe, layer.exe, multi_password_cracker.exe, norton_2004_setup.exe, sin.exe, smurf.exe, suf.exe, syn.exe, covert.dll
Misc:
The covert.dll file is a rootkit. Disabling it unhides other Mogi files.
Files dragon_naturallyspeaking_xp.exe, norton_2004_setup.exe and multi_password_cracker.exe are distributed through file sharing networks. Do not download and execute them!

Exact file location:
dragon_naturallyspeaking_xp.exe, norton_2004_setup.exe, multi_password_cracker.exe - shared folders of installed peer-to-peer applications
other files - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32

Other programs to remove Mogi:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 22/11/05
Information updated: 22/11/05

Additional resources related to Mogi:

Attention: If you know or you have a website or page about Mogi removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Mogi parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: