A handy application that tagrets the Korgo worm #Korgo antivirus #Korgo remover #Korgo worm #Korgo #Antivirus #Remover
Korgo Removal Tool is a lightweight utility that can easily find and eliminate the Win32.Worm.Korgo infection from your system.
The worm exploits the Microsoft LSASS Windows vulnerability for spreading.
Once run, the worm will do the following:
1. Attempts to delete Go.exe from current location
2. Creates the mutexes:
variant A: r10, rocket10 variant B: r10, u2, uterm5
3. Checks if the [HKLM \SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"WinUpdate"] entry exists
If the key exists:
Attempts to delete the registry entry: [HKLM\Software\Microsoft\Wireless\"Server"]
If the key doesn't exist, it attempts to create it:
[HKLM\Software\Microsoft\Wireless\"Server"="1"]
4. Creates a randomly named copy of the worm in %SYSTEM% folder, as ????????.exe where ? may be any letter.
5. Creates the registry entry
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"WinUpdate"="%SYSTEM%\????????.exe"]
in order to run at startup.
6. Executes the copy of the worm and terminates the current process.
7. Starts many threads, and enters an infinite loop, preventing the system from shutting down.
8. Opens ports: 113, 3067, 2041, allowing remote connection and for sending the worm, scans random IP addresses in order to infect unpatched systems. Also opens port 6667, as it attempts to connect to a list of IRC servers where it listens for commands.
- runs on:
- Windows All
- file size:
- 60 KB
- filename:
- antikorgo-en.exe
- main category:
- Antivirus
- developer:
- visit homepage
Bitdefender Antivirus Free
7-Zip
ShareX
Zoom Client
Microsoft Teams
IrfanView
4k Video Downloader
Windows Sandbox Launcher
calibre
Context Menu Manager
- Windows Sandbox Launcher
- calibre
- Context Menu Manager
- Bitdefender Antivirus Free
- 7-Zip
- ShareX
- Zoom Client
- Microsoft Teams
- IrfanView
- 4k Video Downloader