Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 20 April 2005 13:58:15 (GMT) |
| Last updated | 11 May 2005 01:26:10 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Change any data that may have become compromised.
Replace the Hosts file from a backup or edit it in Notepad to remove the changes that the worm has made.
To renable DCOM you can edit the registry, but it's better to use Dcomcnfg.exe. See Microsoft article 825750 for details.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
and remove any reference to any file you deleted.
Close the registry editor.
More Information
W32/Agobot-RR is a member of the W32/Agobot family of network worms. The worm can spread to weakly protected network shares and open Microsoft SQL servers, to computers vulnerable to the RPC-DCOM exploit, and via NetBIOS.
The following patches for the operating system vulnerabilities exploited by W32/Agobot-RR can be obtained from the Microsoft website:
In order to run automatically when Windows starts up the worm copies itself to the Windows SYstem folder as ggtb32.exe and creates the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
google toolbar
ggtb32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
google toolbar
ggtb32.exe
Once installed, W32/Agobot-RR connects to a preconfigured IRC server and joins a channel from which an attacker can issue further commands. These commands can cause the infected computer to perform any of the following actions:
Modify the computer's HOSTS file to deny access to certain computer security websites
Execute, upload, and download files
Log any keystrokes made on an infected computer
Scan for remote computers to infect
Particiapte in Distributed Denial-of-Service (DDoS) attacks
Add and delete services via the Service Control Manager
Search the registry, and delete autostart registry entries
Shutdown, reboot, or log off an infected computer
List and terminate running processes
Act as a SOCKS, HTTP, or FTP proxy server
Harvest email addresses
When the HOSTS file (located in '
The worm can be commanded to secure an infected computer from further infection, or open it up for further infection. Securing an infected computer involves deleting any network shares and disabling DCOM by setting the following registry entry:
HKLM\Software\Microsoft\OLE
EnableDCOM
N
To allow further infection on an infected computer C$, D$, E$, ADMIN$ and IPC$ network shares are added, and DCOM is enabled by setting the following registry entry:
HKLM\Software\Microsoft\OLE
EnableDCOM
Y
