ferrohe.blogg.se

Agobot ku worm
Agobot ku worm




  1. AGOBOT KU WORM PC
  2. AGOBOT KU WORM WINDOWS

  • MYPOO - adds ""="" where is configurable.
  • KILLAV.D - adds ""="%Windir%\" where %Windir% is C:\Windows or C:\Winnt.
  • MYDOOM.F or MYDOOM.G or MYDOOM.H - adds ""="".
  • COREFLOO-C - adds ""="rundll32 %SYSTEM%.
  • SINCOM - adds random name and filename in C:\Windows or C:\Winnt with "Run:Auto" appended to the command/data column entry.
  • WANADO or REUR - adds "XXXXXXXX"="%Sysdir%\XXXXXXXX.exe" where X can be any random hexadecimal (0-9, A-F) number.
  • ZOMBAM.B - adds random name and filename.
  • GIBE.C - adds random name and filename in C:\Windows or C:\Winnt.
  • DEBORMS.D - adds one of a number of valid Name/Startup Item entries but points to the path of the worm file dropped.
  • MOSUCK - random name and filename in C:\Windows or C:\Winnt.
  • nCase (or n-Case) parasite - adds multiple and random startup entries.
  • FreeScratchAndWin - adds multiple and random startup entries as it includes LOP above.
  • Lop.com homepage hijacker - adds multiple and random startup entries.
  • OPTIXPRO.11 - adds "%Registry entry%"="%Path%\%Filename%".
  • BUGBEAR.A or BUGBEAR.C or BUGBEAR.E - adds " "=%System%\".EXE".
  • PE_BISTRO - adds "XXXX"="C:\WINDOWS\XXXX.EXE" - where XXXX is the randomly chosen filename of the dropped file.
  • In all cases below, %system% is a variable - by default this is C:\Windows\System (Win9x/Me), C:\Winnt\System32 (WinNT/2K), or C:\Windows\System32 (WinXP): They make additional entries under the registry key HKLM\Software\Microsoft\Windows\CurrentVersion\ Run and RunOnce keys, allowing them to run at startup.

    agobot ku worm

    There are viruses and other pests that can add any number of different entries to the startups.

    AGOBOT KU WORM WINDOWS

    To avoid the list becoming too large, all VIRUSES are shown using the registry version which is common to all Windows versions. For example, WinMe lists "POPROXY.EXE" as "Norton eMail Protect" in both MSCONFIG and the registry whereas WinXP lists it as "Poproxy" in MSCONFIG and "Noeton eMail Protect" in the registry. Operating System DifferencesĪ number of entries are repeated due to the way that different operating systems display startup items. An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. Therefore, before ending a task/process via CTRL+ALT+DEL just because it has an "X" recommendation, please check whether it's in MSCONFIG or the registry first. For a list of tasks/processes you should try WinTasks 5 Standard/Professional from LIUtilities or the list at AnswersThatWork. Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. This is NOT a list of tasks/processes taken from Task Manager or the Close Program window ( CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed via this method.

    AGOBOT KU WORM PC

    This page presents a searchable, comprehensive list of the programs you may find that run when you switch on your PC as typically identified by MSCONFIG or the registry "Run" keys - and whether you need them. Startups - All Start-Up Applications - All






    Agobot ku worm