you know that he must have got something knock in to that brain of his.
because he would not rest like the doctor and all of us told him to do.
he kept working at the computer and got it scanned online before it crashed.
housecalls or antivirus.com has posted that he has got the newest version of this.
trojon back door so now i will have to walk him through the steps to remove it.
then all might be good again.
by the way norton and others can not find the newst one of this. just trend micro. this new one even shuts down zonealarm.exe and lots of other ones it is a bad one.
QUICK LINKS Solution
--------------------------------------------------------------------------------
Virus type: Worm
Destructive: No
Aliases: W32/Agobot.CQ, Worm.Win32.Agobot.205824, W32/Gaobot.BZ.worm
Pattern file needed: 715
Scan engine needed: 5.600
Overall risk rating: Low
--------------------------------------------------------------------------------
Reported infections: Low
Damage Potential: High
Distribution Potential: High
--------------------------------------------------------------------------------
Description:
This memory-resident worm exploits certain vulnerabilities to propagate across networks. Like the earlier AGOBOT variants, it takes advantage of the following Windows vulnerabilities:
Remote Procedure Call (RPC) Distributed Component Object Model (DCOM) vulnerability
IIS5/WEBDAV Buffer Overflow vulnerability
RPC Locator vulnerability
For more information about these Windows vulnerabilities, please refer to the following Microsoft Web pages:
Microsoft Security Bulletin MS03-026
Microsoft Security Bulletin MS03-001
Microsoft Security Bulletin MS03-007
It attempts to log in on systems using a predefined list of user names and passwords.
It also has backdoor capabilities and may execute malicious commands on the host machine. It terminates antivirus-related processes and dropped files by other malware. It also steals CD keys of certain game applications.
It only runs on Windows NT, 2000 and XP
Solution:
AUTOMATIC REMOVAL INSTRUCTIONS
To automatically remove this malware from your system, please use Trend Micro Damage Cleanup Services.
MANUAL REMOVAL INSTRUCTIONS
Identifying the Malware Program
To remove this malware, first identify the malware program.
Scan your system with your Trend Micro antivirus product.
NOTE all files detected as WORM_AGOBOT.BU.
Trend Micro customers need to download the latest pattern file before scanning their system. Other Internet users may use Housecall, Trend Micro’s free online virus scanner.
Terminating the Malware Program
This procedure terminates the running malware process from memory.
Open Windows Task Manager.
To do this, press
CTRL+SHIFT+ESC, and click the Processes tab.
In the list of running programs, locate the process:
WUMP.EXE
Select the malware process, then press either the End Task or the End Process button, depending on the version of Windows on your system.
To check if the malware process has been terminated, close Task Manager, and then open it again.
Close Task Manager.
*NOTE: On systems running Windows 9x/ME, Task Manager may not show certain processes. You may use a third party process viewer to terminate the malware process. Otherwise, continue with the next procedure, noting additional instructions.
Removing Autostart Entries from the Registry
Removing autostart entries from the registry prevents the malware from executing during startup.
Open Registry Editor. To do this, click Start>Run, type Regedit, then press Enter.
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>Run
In the right panel, locate and delete the entry:
Configuration Loader = "wump.exe"
In the left panel, double-click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>
Windows>CurrentVersion>RunServices
In the right panel, locate and delete the entry:
Configuration Loader = "wump.exe"
Close Registry Editor.
NOTE: If you were not able to terminate the malware process from memory as described in the previous procedure, restart your system.
Additional Windows ME/XP Cleaning Instructions
Running Trend Micro Antivirus
Scan your system with Trend Micro antivirus and delete all files detected as WORM_AGOBOT.BU. To do this, Trend Micro customers must download the latest pattern file and scan their system. Other Internet users can use HouseCall, Trend Micro’s free online virus scanner.
Applying Patches
Download the latest patch. Information and download links on the vulnerabilities exploited by the malware can be found at the following links:
Microsoft Security Bulletin MS03-026
Microsoft Security Bulletin MS03-001
Microsoft Security Bulletin MS03-007
Trend Micro offers best-of-breed antivirus and content-security solutions for your corporate network, small and medium business or home PC.
Archived topic from Iceteks, old topic ID:1993, old post ID:16732