%SysDir%\gcasSav32.exe |
| Name |
%SysDir%\gcasSav32.exe |
Description
|
gcasSav32.exe is a mass-mailing worm W32.Kedebe.B@mm. gcasSav32.exe tries to terminate antiviral programs installed on a user computer. gcasSav32.exe opens a back door on a random TCP port. Related files: %System%\winssc32.exe %System%\mscppmgr.exe %System%\kerne132.exe %System%\NAVMON.EXE %System%\drwmgr32.exe %System%\DLLH0ST.EXE %System%\gcasctrl.exe %System%\msscan.exe %System%\cuApp.exe %System%\LSSAS.EXE %System%\AVmon.exe %System%\SERVlCES.EXE %System%\gcasSav32.exe %System%\LUC0MS~1.EXE %System%\zlbclient.exe %System%\mantispam.exe %System%\NETM0N.EXE %System%\srvchost.exe %System%\USRMGRINIT.JFX Admin Password Cracker.exe DVD ripper keygen.exe Messenger 7.0 Installer.exe Microsoft AntiSpyware Patch.com Mydoom removal tool.exe Naked teen-Actions.com Norton Personal Firewall 2005 Patch.exe Spyware remover.exe Win Server 2003 Remote Exploit.cmd ZoneAlarm Security Suite 2005 Crack.com Adds the value: "Windows [worm filename without extension] Monitor" = "[file name of the worm]" "Run" = "[file name of the worm]" to the Windows startup registry keys. More info: http://securityresponse.symantec.com/avc... Removal: Kill gcasSav32.exe process and remove gcasSav32.exe from Windows startup using antivirus (also check How To Remove section)Startup Optimizer. |
|
|
|
|