TheTechGuide Forum
General Category => Software => Topic started by: Andrew on June 14, 2004, 12:30:00 PM
-
Is anyone aware of a worm that behaves as follows:
Somehow, a batch file, c.bat, and a file called " .pif" are present in the windows\system32 directory. The .pif file contains a script to ftp to a server ( in this case, it was a local machine on my network) and download a file called spsc.exe This is invoked through c.bat, after which point c.bat and .pif are deleted. I have yet to determine what, if any, harm is done by this worm.
-
Go to it.trendmicro-europe.com/enterprise/security_info/vedetail.php?Vname=WORM_AGOBOT.WF. It will tell you all about it. You need to download Symantec file FXGAOBOT.EXE and if running Windows XP download patch in article KB835732. Good Luck