SoftwareTipsandTricks.com
Home Forums Windows 7 Security Tips
Forums

Windows 7
Windows Vista
Windows XP

Security Tips
Troubleshooting
Keyboard Shortcuts
Encyclopedia


Drivers

Internet Terms
Computer Terms

File Extensions (75)
File Extensions (15K+)

Startup Applications
Necessary Files
Useless Files
At Your Option Files
Dangerous Files
Browser Objects

DLL Files
SYS Files
INF Files
OCX Files
VXD Files

Virus Database
Virus Warnings

Easter Eggs
Tips and Tricks
Articles
Hot Downloads


Privacy Policy
Contact Us







  confgldr.exe

Name confgldr.exe

Description

W32.Gaobot.gen!poly is a worm that attempts to spread through network shares with weak passwords and allows attackers to access
an infected computer using a specific IRC channel.
Allows an attacker to remotely control a compromised computer and perform any of the following actions:
- Download and execute files
- Steal system information
- Harvest email addresses
- Steal CD keys for various games

Also Known As: W32.HLLW.Polybot, Phatbot, W32/Polybot.l!irc [McAfee], WORM_AGOBOT.HM [Trend], Backdoor.Agobot.hm [Kaspersky]

Copies itself as one of the following files:
%System%\soundman.exe
%System%\confgldr.exe
%System%\spoolsvc.exe

Adds one of the following values:
"^`d}qZxu" = "~`d}qzxu3zYF"
"Configuration Loader"="confgldr.exe"
"Video Process"="sysconf.exe"
"Service Host Process"="spoolsvc.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices

Creates a service for the worm with one of the following names and sets it to automatically run on startup:
Configuration Loader, SoundMan, Service Host Process

Hides all the files that contain the word "soun."

May change the %System%\drivers\etc\hosts file with some lines.
Attempt to spread to other systems by exploiting vulnerabilities.
Ends processes associated with antivirus and firewall software.
Attempts to delete the files and registry values associated with other worms.

Use antivirus (also check How To Remove section)Startup Optimizer to remove it from startup.
For more information to locate and remove this worm, see on http://securityresponse.symantec.com/avc...


Still have a problem? Ask for help at our discussion forum.



Search Dangerous Files :
 

: : Recent posts at Forums : :

My up to date trap scheme

Казино вулкан

New site

Loose adult galleries

Cheap NFL Jerseys China Online

Сенсация! Дев&

Day after day gay photos usage

Протестируй н

Оборудование

Save me from rewriting all these from scratch please :(

Онлайн игры к&

Lusty men photo blog

Big Black Grls!Old Fat MILF !# 2956269

фэнтези фильм

Сенсация! Дев&

Black Fat - Ebony moms boobs# 7954208

My supplementary website

Fat Pussy BBW!Black Girls photo!# 4090475

Your love sex?..

charmingdate review

What is the purpose of Bitcoin Gold?

What is the purpose of Bitcoin Gold?

What is the purpose of Bitcoin Gold?

Лучшие ужасы 2

What is the purpose of Bitcoin Gold?

What is the purpose of Bitcoin Gold?

Протестируй н

Grown up galleries

barely an expresssion of this and may peradventure

Cheap NFL Jerseys China Wholesale




SoftwareTipsandTricks, All Rights Reserved.