Re: Realplayd.exe = new AGOBOT variant?
From: Br0wnbear (brownbearat_at_canadadotcom.net)
Date: 11/11/04
- Next message: David H. Lipman: "Re: Realplayd.exe = new AGOBOT variant?"
- Previous message: Malke: "Re: Script Blocking-File Object: Create Text File --Juno 5.0 Software?"
- In reply to: Ryrobes: "Realplayd.exe = new AGOBOT variant?"
- Next in thread: David H. Lipman: "Re: Realplayd.exe = new AGOBOT variant?"
- Reply: David H. Lipman: "Re: Realplayd.exe = new AGOBOT variant?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Wed, 10 Nov 2004 21:51:18 -0500
On 10 Nov 2004 09:48:42 -0800, erirobitair@yahoo.com (Ryrobes) wrote:
>I have been getting alerts on our network that DOS_AGOBOT.GEN has
>infected some machines - unfortunately our TrendMicro OfficeScan does
>not detect the actual EXE that is doing the job, but only detects the
>crap that the worm appends to the users HOSTS file (redirecting
>anti-virus sites to localhost, etc.)...
>
>The culprit: "realplayd.exe" is about 100k (standard for AGOBOT
>varaints i think), it puts itself into the 'system32' folder as well
>as the root of the 'winnt' folder, usually it CAN be killed and then
>editied OUT of the registry so I won't run again, but all I can see
>damaged is the HOSTS file, has anyone else seen this variant yet?
>
>If it is just a standard re-implementation of one of the AGOBOTs, what
>else should I be doing (besides patching that is)?
Ryrobes
I would submit the file to one of the AV sites for analysis. They will
be able to give you an indepth analysis of the file.
hth
John Brown
"Bears have more fun, we hibern8 alot"
- Next message: David H. Lipman: "Re: Realplayd.exe = new AGOBOT variant?"
- Previous message: Malke: "Re: Script Blocking-File Object: Create Text File --Juno 5.0 Software?"
- In reply to: Ryrobes: "Realplayd.exe = new AGOBOT variant?"
- Next in thread: David H. Lipman: "Re: Realplayd.exe = new AGOBOT variant?"
- Reply: David H. Lipman: "Re: Realplayd.exe = new AGOBOT variant?"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|