The Web    Google
6/4: Agobot.300544 a Memory Resident

6/4: Agobot.300544 a Memory Resident
June 4, 2004

Worm/Agobot.300544 is a memory resident Internet worm that spreads by capitalizing on various Microsoft vulnerabilities, as well as through network shares. If executed, the worm copies itself in the \windows\%system% directory under the filename "asp-srvc.exe" and in C:\WINNT\System32\drivers\etc\hosts.

So that it gets run each time a user restart their computer the following registry keys get added:

- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "asp-srvc"="asp-srvc.exe"

- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices "asp-srvc"="asp-srvc.exe"

Certain keys are also get added. View them and other information at Central Command page.

  • In 2005, Organized Crime Will Back Phishers
  • 3/29: Krynos-B Worm Drops Copy of Itself
  • Bush Seeks IT Security Advice
  • 1/11: Agobot-OV Worm Connects to IRC Server
  • AutoCert Automates Certificate Renewal
  • NIKSUN offers a security camera for your network
  • Government Against Full Disclosure of Vulnerabilities
  • 5/17: Vidlo-J a Downloading Trojan
  • Virus Alert Activity Intensifies
  • 1/6: Rbot-SX Worm Spreads to Shares
  • HP Cuts to the Middle of Disaster Recovery
  • Compare Security Camera Products