We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Gaobot.FC
Aliases: WORM_AGOBOT.FC (Trend Micro) W32/Gaobot.worm.gen.d (McAfee) Win32/Agobot.FA.Worm (CA) WORM_AGOBOT.CE (Trend Micro) Win32/Agobot.EX.Worm (CA) WORM_AGOBOT.AH (Trend Micro) Backdoor/Agobot.78501 (CA) Backdoor/Agobot.78493.Server (CA)
Summary
- Disconnect from the Internet
-
End the worm process
-
Delete the worm files from the hard disk
-
Delete the worm registry entry
-
Take steps to prevent re-infection
Disconnect from the Internet
End the worm process
-
Press CTRL+ALT+DEL once and click Task Manager.
-
Click Processes and click Image Name to sort the running processes by name.
-
Select the process sound.exe, and click End Process.
-
Select the process syscf32.exe, and click End Process.
-
Select the process wind32.exe, and click End Process.
-
Select the process wupdate32.exe, and click End Process.
- Delete the worm files from the hard disk
To delete the worm files from the hard disk
-
Click Start, and click Run.
-
In the Open field, type %windir%\system32
-
Click OK.
-
Click Name to sort files by name.
-
If sound.exe is in the list, delete it.
-
If syscf32.exe is in the list, delete it.
-
If wind32.exe is in the list, delete it.
-
If wupdate32.exe is in the list, delete it.
-
On the Desktop, right-click the Recycle Bin and click Empty Recycle Bin.
-
Click Yes.
-
Press CTRL+ALT+DEL once and click Task Manager.
-
Click Processes and click Image Name to sort the running processes by name.
-
Confirm that sound.exe is not in the list.
-
Confirm that syscf32.exe is not in the list.
-
Confirm that wind32.exe is not in the list.
-
Confirm that wupdate32.exe is not in the list.
Delete the worm registry entry
-
On the Start menu, click Run.
-
Type regedit and click OK.
-
In the left pane, navigate to the key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
In the right pane, right-click the following values, if they exist:
System Configuration
Windows Registry Startup
Windows Sound Manager
Windows Update Manager -
Click Delete and click Yes to delete the value.
-
In the left pane, navigate to the key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
In the right pane, right-click the following values, if they exist:
System Configuration
Windows Registry Startup
Windows Sound Manager
Windows Update Manager -
Click Delete and click Yes to delete the value.
-
Close the Registry Editor.