| |
Descrizione: |
Worm/Agobot.300544 is a memory resident Internet worm that spreads by capitalizing on various Microsoft vulnerablities, as well as, through network shares.
If executed, the worm copies itself in the \windows\%system% directory under the filename "asp-srvc.exe" and in C:\WINNT\System32\drivers\etc\hosts.
So that it gets run each time a user restart their computer the following registry keys get added:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"asp-srvc"="asp-srvc.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
"asp-srvc"="asp-srvc.exe"
Worm/Agobot.300408 will open TCP ports 113, 7088, 23289.
|