|
||
6/4: Agobot.300544 a Memory Resident Worm/Agobot.300544 is a memory resident Internet worm that spreads by capitalizing on various Microsoft vulnerabilities, as well as through network shares. If executed, the worm copies itself in the \windows\%system% directory under the filename "asp-srvc.exe" and in C:\WINNT\System32\drivers\etc\hosts.
So that it gets run each time a user restart their computer the following registry keys get added:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "asp-srvc"="asp-srvc.exe"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices "asp-srvc"="asp-srvc.exe"
Certain keys are also get added. View them and other information at Central Command page.
|
||
|