The WebDav vulnerability (described in Microsoft Security Bulletin MS03-007), using TCP port 80. Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, Symantec suggests sharing with Read Notes: Virus Definitions released before March 24, 2004 detect this threat as W32.HLLW.Polybot. WORM_AGOBOT.CZ Alias:Backdoor.Win32.Agobot.aid (Kaspersky), W32/Gaobot.worm.gen.e (McAfee), W32.HLLW.Gaobot.gen (Symantec), Worm/AgoBot.aid.1 (Avira), W32/Agobot-AID (Sophos), Worm:Win32/Spybot (Microsoft...

WORM_AGOBOT.AUU Alias:W32.HLLW.Gaobot.gen, W32/Agobot-Fam, W32/Gaobot.worm, Win32.Agobot.genDescription: This worm propagates via network shares. Comments « AVG Anti-Virus Update January 18, 2017 · Symantec W32.Gaobot Removal Tool 1.30.0 · Jetico Personal Firewall » MajorGeeks.Com » Antivirus » Symantec Removal Tools » Symantec W32.Gaobot Removal The vulnerabilities in the Microsoft SQL Server 2000 or MSDE 2000 audit (described in Microsoft Security Bulletin MS02-061), using UDP port 1434. The WebDav vulnerability (described in Microsoft Security Bulletin MS03-007) using TCP port 80. https://www.symantec.com/security_response/writeup.jsp?docid=2003-112112-1102-99

For more information, read the Microsoft knowledge base article: XADM: Do Not Back Up or Scan Exchange 2000 Drive M (Article 298924).Follow these steps to download and run the tool:Download the Disable or password-protect file sharing, or set the shared files to Read Only, before reconnecting the computers to the network or to the Internet. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP). %Temp% is a variable that refers to the temporary folder in the short path form.

The worm specifically targets Windows 2000 machines using this exploit. By default, the worm listens on TCP port 63809 and notifies the attacker through IRC. Most variants are packed with a run-time packer, such as UPX. This worm propagates using multiple vulnerabilities, including: Weak passwords on network shares The DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026), using TCP ports 135 and 445.

This worm also opens a backdoor to a predetermined IRC channel.

It searches... Then, scan the computer with AntiVirus with current virus definitions. WinSysClean3. Windows XP users are protected against this vulnerability if Microsoft Security Bulletin MS03-043 has been applied.

The worm uses multiple vulnerabilities to spread, including: The DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135.

Please enable JavaScript to view the comments powered by Disqus. The backdoor ports that the Beagle and Mydoom families of worms open. Symantec recommends that you use only copies of the removal tool that have been directly downloaded from the Symantec Security Response Web site.If you are not sure, or are a network The Microsoft Messenger Service Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-043).

