View Full Version : wmon32.exe
rio_bugarin
05-31-2004, 04:49 AM
can anyone tell me something about this. Its a backdoor worm but i dont know how it got on my computer.:D
John0904
05-31-2004, 02:39 PM
Either in the e-mail or a downloaded illegitimate program.
YODA74
05-31-2004, 03:14 PM
http://www.sophos.com/virusinfo/analyses/w32agobotit.html
http://webhost.bridgew.edu/ylam/worm_agobot/
PrntRhd
05-31-2004, 05:12 PM
Gaobot/Argobot spreads via several means, especially Windows computers that are not patched (RPC) & (DCOM). It comes in through your Internet connection, not your e-mail. It changes your HOSTS file to lock out security/AV applicatons and updates, making removal difficult.
symantec (http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.ajj.html)[QUOTE]
"The backdoor allows an attacker to perform the following actions on the compromised system:
* Run commands
* Retrieve files through FTP and HTTP
* Retrieve data from the registry
* Restart the computer
* List the processes
* Kill a particular process
* Terminate Windows services
* Perform HTTP, ICMP, SYN, and UDP floods
* Retrieve the email addresses stored on the computer
* Retrieve a list of email addresses through HTTP
* Retrieve a given URL
* Sniff HTTP, FTP, and IRC traffic
* Steal the Windows product ID and the CD keys of various video games"
rio_bugarin
06-05-2004, 04:54 AM
thx. i never taught it could do that much. i taught it only consumes most of your processing power:D
vBulletin v3.6.1, Copyright ©2000-2009, Jelsoft Enterprises Ltd.