Be A BoredGuru
 Be A BoredGuru  Register      
Main Menu
Home
ePals
Inbox
Send Message
My Profile

News
Submit
Archive
Topics

Articles
Submit
Archive
Topics

Classifieds
Search

Forum
Most Recent
Most Viewed
Most Active
Search

Downloads
Submit
Popular
Top Rated

Web Links
Submit
Popular
Top Rated

Blog
Choose Blog

Gallery
Events
Add an event

FAQ
Goa Hotels

ePals Ad

Who's Online
 Guest (s): 12
 Member (s):0
 21983: Members

You are Visitor.
From : United States United States
Register Now.

Last Saw : xtractbkf, elevate, easyjobs091, rattikashyap, convertor, Localsecurity, samresh50, Wholesaleun, Ducatjaipur, skyinfotech123

Welcome to BoredGuru.com : Removal of winmon.exe ( W32/Agobot-KA) - a Trojan
 
BoredGuru.com : Forum : Windows : Removal of winmon.exe ( W32/Agobot-KA) - a Trojan  Forum Index
   BoredGuru.com : Forum : Windows : Removal of winmon.exe ( W32/Agobot-KA) - a Trojan  Windows
BoredGuru.com : Forum : Windows : Removal of winmon.exe ( W32/Agobot-KA) - a Trojan  Removal of winmon.exe ( W32/Agobot-KA) - a Trojan
Register To Post

yogi Removal of winmon.exe ( W32/Agobot-KA) - a Trojan

Masters of BG


Joined: 02-Jan-2004
Posts: 442
From: Chennai, India


Description
W32/Agobot-KA is a backdoor Trojan and worm which spreads to computers
protected by weak passwords.
When first run, W32/Agobot-KA moves itself to the Windows system folder
as winmon.exe and creates the following registry entries to run itself on
startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Windows Monitor = winmon.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
Windows Monitor = winmon.exe

Each time the Trojan is run it attempts to connect to a remote IRC server
and join a specific channel.

The Trojan then runs continuously in the background, allowing a remote
intruder to access and control the computer via IRC channels.

The Trojan attempts to terminate and disable various anti-virus and
security-related programs and modifies the HOSTS file located at
%WINDOWS%\System32\Drivers\etc\HOSTS, mapping selected anti-virus
websites to the loopback address 127.0.0.1 in an attempt to prevent access
to these sites.

Removal Instructions

Please follow the instructions for removing worms.

Replace the Hosts file from a backup or edit it in Notepad to remove the changes that the worm has made.

Check your administrator passwords and review network security.

You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entries:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Windows Monitor = winmon.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
Windows Monitor = winmon.exe

and delete them if they exist.

Close the registry editor.

Warning: Back up the registry first.

Is it really worth your time and money (you could lose all your money in the bank if your password is compromised) to be worrying about these things?

It is always better to have a software that can protect your computer and you. Spywares are more dangerous than viruses, coz of the simple reason that they steal your information. Your banking account password is much more worthy to them than your computer. And thats what most of them are after.











WinTasks
Professional
- Security
Made Easy

  • remove and block spyware, adware, malware,
    and more

  • identify the threats with detailed process
    information

  • approve every process on your computer

  • automatic updates give up-to-the-minute
    protection

  • very easy to use










  • Other Software from /uniblue Systems: WinBackup,
    SpeedUpMyPC,
    Utility
    Pack


    [ Edited by yogi on 2004/12/21 2:27 ]
    2004/7/13 19:29 Profile Visit Website

    yogi Reg file for removing winmon.exe.

    Masters of BG


    Joined: 02-Jan-2004
    Posts: 442
    From: Chennai, India


    As the winmon.exe tries not to let you open regedit in some cases please use this reg file foubd here in our downloads section. you just download it and unzip it and run it.
    Warning : Back up your registry first.

    the link is here : Reg file for Removal of winmon.exe a Trojan
    2004/7/14 8:28 Profile Visit Website

    Pezzz Re: Reg file for removing winmon.exe.

    Stranger


    Joined: 15-Apr-2005
    Posts: 1
    From: Australia


    might be a silly question, but if you can't access regedit, how r u supposed to back up registry ???


    "As the winmon.exe tries not to let you open regedit .......... Warning : Back up your registry first."

    As i said .. just curious .. cheers :)
    2005/4/15 17:27 Profile

    yogi Re: Reg file for removing winmon.exe.

    Masters of BG


    Joined: 02-Jan-2004
    Posts: 442
    From: Chennai, India


    gotcha.
    Seems like we will have to learn how to backup without opening the registry.
    Any ideas?
    2005/4/15 20:02 Profile Visit Website

    imthiaz Re: Reg file for removing winmon.exe.

    Masters of BG


    Joined: 31-Dec-2003
    Posts: 395
    From: Sharjah, UAE


    We can copy the files fully where windows is storing...

    look here where the files are placed...

    http://www.easydesksoftware.com/regfiles.htm

    Hope this helps...
    2005/4/16 10:09 Profile Visit Website

      

    Cassini Saturn Photos Gallery
    View the Cassini_Saturn_Photos gallery

    Classified Ads Section
    Offered : Simple copy paste job.
    Offered : erp training
    Offered : erp training
    Offered : erp training
    Offered : erp training

    All the ads...

    Polls

    Event Calendar
    February 2010
    MoTuWeThFrSaSu
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    22
    23
    24
    25
    26
    27
    28

    Privacy Policy Disclaimer
    Best Viewed at 1024 X 768 screen resolution.
    Powered by E-Xoops 1.05 Rev3 © 2003 E-Xoops.com