|
|
Welcome to BoredGuru.com : Removal of winmon.exe ( W32/Agobot-KA) - a Trojan |
|
| yogi |
Removal of winmon.exe ( W32/Agobot-KA) - a Trojan |

Masters of BG
Joined: 02-Jan-2004
Posts: 442
From: Chennai, India
|
| |
Description W32/Agobot-KA is a backdoor Trojan and worm which spreads to computers protected by weak passwords. When first run, W32/Agobot-KA moves itself to the Windows system folder as winmon.exe and creates the following registry entries to run itself on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ Windows Monitor = winmon.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ Windows Monitor = winmon.exe
Each time the Trojan is run it attempts to connect to a remote IRC server and join a specific channel.
The Trojan then runs continuously in the background, allowing a remote intruder to access and control the computer via IRC channels.
The Trojan attempts to terminate and disable various anti-virus and security-related programs and modifies the HOSTS file located at %WINDOWS%\System32\Drivers\etc\HOSTS, mapping selected anti-virus websites to the loopback address 127.0.0.1 in an attempt to prevent access to these sites.
Removal Instructions
Please follow the instructions for removing worms.
Replace the Hosts file from a backup or edit it in Notepad to remove the changes that the worm has made.
Check your administrator passwords and review network security.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ Windows Monitor = winmon.exe
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\ Windows Monitor = winmon.exe
and delete them if they exist.
Close the registry editor.
Warning: Back up the registry first.
Is it really worth your time and money (you could lose all your money in the bank if your password is compromised) to be worrying about these things?
It is always better to have a software that can protect your computer and you. Spywares are more dangerous than viruses, coz of the simple reason that they steal your information. Your banking account password is much more worthy to them than your computer. And thats what most of them are after.
 | WinTasks Professional - Security Made Easy |
remove and block spyware, adware, malware, and more identify the threats with detailed process information approve every process on your computer automatic updates give up-to-the-minute protection very easy to use
| |
[ Edited by yogi on 2004/12/21 2:27 ] |
|
| 2004/7/13 19:29 |
|
|
|
|