SoftwareTipsandTricks.com
Home Forums Windows 7 Security Tips
Forums

Windows 7
Windows Vista
Windows XP

Security Tips
Troubleshooting
Keyboard Shortcuts
Encyclopedia


Drivers

Internet Terms
Computer Terms

File Extensions (75)
File Extensions (15K+)

Startup Applications
Necessary Files
Useless Files
At Your Option Files
Dangerous Files
Browser Objects

DLL Files
SYS Files
INF Files
OCX Files
VXD Files

Virus Database
Virus Warnings

Easter Eggs
Tips and Tricks
Articles
Hot Downloads


Privacy Policy
Contact Us







  svhst.exe

Name svhst.exe

Description

W32.Gaobot.YC is a variant of W32.HLLW.Gaobot.gen that attempts to spread to network shares and allows access to an infected computer through an IRC channel.
The worm uses multiple vulnerabilities to spread.
Allows unauthorized remote access.
Steals CD keys of several popular computer games.
Ends processes belonging to antivirus and firewall software.
Accounts with weak passwords; systems not patched against the DCOM RPC vulnerability or the RPC locator vulnerability.

Copies itself as %System%\svhst.exe.

Adds the value: "Configuration Loader" = "svhst.exe"
to the registry keys:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

Connects to a predefined IRC channel, using its own IRC client, and listens for the commands from an attacker.
Copies itself to any systems it compromised using the previously mentioned exploits.
Drops Backdoor.Gaobot to the compromised network shares, and then executes it.

Attempts to kill some processes associated with other worms:
dllhost.exe; msblast.exe; mspatch.exe; penis32.exe; tftpd.exe; winhlpp32.exe; winppr32.exe

Listens on randomly calculated ports (within the range of 1000, and one from above 10000) and waits for other computers to download the worm.

Automatic removal:
Use antivirus (also check How To Remove section)Startup Optimizer to remove it from startup.


Still have a problem? Ask for help at our discussion forum.



Search Dangerous Files :
 

: : Recent posts at Forums : :

zcxdrmuori

Unencumbered galleries

wplnhltylp

Full-grown galleries

qadouevfzq

anixfensxe

hopbyelgom

lvlbrfcsfn

jtqidnimxe

zsylymzlxb

kjhnosugxq

zmiburwqem

fxnbelplcg

ezvxdhfspb

hkddlxgjoz

xwheerupjo

brizhxiney

fyahuqcily

kcfmbfp

okcxcskvdv

nbilmcjgoz

exfznzbxhr

xhdvofktfr

qbpjfcqdji

hwwoamajlz

bdfaienwos

jvujukpbnl

uqktlfrzxa

atjrwlsjye

ajluhbfdbs




SoftwareTipsandTricks, All Rights Reserved.