Skip to main content
Skip to main content
Published Jan 25, 2005 | Updated Sep 15, 2017

Worm:Win32/Korgo.AB

Detected by Microsoft Defender Antivirus

Aliases: W32/Korgo.worm.ad (McAfee)

Summary

Win32/Korgo.AB.worm is a network worm that targets computers running Microsoft Windows XP or Windows 2000 that do not have Microsoft Security Bulletin MS04-011 installed. The worm monitors TCP ports and opens a backdoor to allow unauthorized access to infected computers. A computer infected with this worm may crash and reboot unexpectedly.
To manually recover from infection by Win32/Korgo.AB.worm, perform the following steps:
  1. Stop the computer from restarting.
  2. Disconnect from the Internet.
  3. Restart your computer.
  4. Take steps to prevent re-infection.

Stop the computer from restarting

First, prevent the computer from spontaneously rebooting by disabling system shutdown.
To disable system shutdown
  1. Click Start, and then click Run.
  2. In the Open field, type shutdown -a
  3. Press Enter.

Disconnect from the Internet

To help ensure that your computer is not actively infecting other computers, disconnect it from the Internet before proceeding. Print this Web page or save a copy on your computer; then unplug your network cable and disable your wireless connection. You can reconnect to the Internet after completing these steps.

Restart your computer

To restart your computer
  1. On the Start menu, click Shut Down.
  2. Select Restart from the drop-down list and click OK.

Take steps to prevent re-infection

Do not reconnect your computer to the Internet until the computer is protected from re-infection. See the "Preventing Infection" section for more information.
Follow us