Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Win32/Gaobot, Agrobot, Agobot virus info.. |
|---|---|
| Date: | Fri, 17 Dec 2004 05:58:58 -0800 (PST) |
Hello,
My LAN has been experiencing problems with this virus the last couple days.
I've looked for
specific info on the virus being reported as "Win32/Agobot.NPM trojan" by
Eset's NOD32 without
much luck. A couple workstations were indeed infected and I have used tools
such as F-Secure's
Agobot removal utility which report successful removal. The symptoms seem to be
gone. The fully
infected workstations have the virus as the file "wmon32.exe" which also runs
as a process. After
cleaning the infected workstations, NOD32 on a few of the remaining wks still
report an infected
file as "winhlpp32.exe". However, none of the other symptoms are seen. I'm
beginning to think this
is possibly the first file that the 'worm' tries to drop to infect a
workstation??
My worry:
a) NOD32 reported the virus earlier and even has various definitions for
variants of this but just
identifies this one and does not clean it, why?
b) what are the specific files created by this variant, regkeys, infected files
to be
deleted?.such info
c) prevention of re-infection [ apart from the MS Security update MS04-011]
It?s a big LAN and there's none of that central management stuff right
now?.running a mix of
everything Microsoft?NTWKS, NTSRVR, Win2KPro, W2kSrvr, Win9x.
I'd appreciate useful pointers and info.
Regards,
John
__________________________________
Do you Yahoo!?
Yahoo! Mail - 250MB free storage. Do more. Manage less.
http://info.mail.yahoo.com/mail_250
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | how to filter the xmas virus, lsi |
|---|---|
| Next by Date: | Re: what is the best procedure to track down a potentially new virus/worm/etc?, Caeser Augustus |
| Previous by Thread: | how to filter the xmas virus, lsi |
| Indexes: | [Date] [Thread] [Top] [All Lists] |