PDA

Visualizza versione completa : W32/Agobot.AB@RPC - Rischio 4 - Update


Giorgius
16-10-2003, 18.33.49
Si ricomincia... :rolleyes: (N)

Aliases:
W32/Agobot-AB (Sophos), Worm-Backdoor.W32/Agobot.AB@RPC, Backdoor.Agobot.3.h

Effetti:
W32/Agobot-AB is a variant of the Agobot family of worms with a backdoor component. This version drops the file Iexplorer.exe into the Windows system folder and creates the following registry entries to run automatically when Windows boots up:

HKLM\Software\Microsoft\Windows\CurrentVersion\
Run\Windows Backup Configuration

HKLM\Software\Microsoft\Windows\CurrentVersion\
RunServices\Windows Backup Configuration

Info:
http://www.sophos.com/virusinfo/analyses/w32agobotab.html


Aggiornamento AntiVirus al 16.10.03 ;)(Y)