| Name |
%PROGRAM FILES%\Common Files\services.exe |
Description
|
Mass mailing worm W32.Crowt. Adds the values: "Services Logon" = "%Templates%\services.exe" "Services Startup" = "%CommonProgramFiles%\services.exe" to Windows startup registry keys. %Templates% is a variable that refers to the Templates folder. By default this is C:\Documents and Settings\[user name]\Templates. Opens a browser window displaying a Web page on the www.cnn.com domain. Steals passwords to %Windir%\temp\keys.tmp. Opens a backdoor by connecting to the host cocoazul.ath.cx on TCP port 80. Allows teh remote control. Kill it using antivirus (also check How To Remove section)Startup Optimizer, |
|