Korgo Removal Tool icon

Korgo Removal Tool

2 big stars
Korgo Removal Tool screenshot
Name: Korgo Removal Tool
Works on: windowsWindows 7 and above
Developer: Bitdefender LLC
Version: 1
Last Updated: 27 Feb 2017
Release: 06 Aug 2010
Category: Antivirus > Removal Tools
Rate this software:
1239 downloads
screenshotsView Screenshots(1)
commentsComments
downloadDownload
Liked it? Tell others:
details

Korgo Removal Tool Details

Works on: Windows 10 | Windows 8.1 | Windows 8 | Windows 7 | Windows 2012
SHA1 Hash: 3a3af50b1acf66da95554e9f06c805d4f88664cf
Size: 61.44 KB
File Format: exe
Rating: 2.52173913 out of 5 based on 23 user ratings
Downloads: 1239
License: Free
Korgo Removal Tool is a free software by Bitdefender LLC and works on Windows 10, Windows 8.1, Windows 8, Windows 7, Windows 2012.
You can download Korgo Removal Tool which is 61.44 KB in size and belongs to the software category Removal Tools.
Korgo Removal Tool was released on 2010-08-06 and last updated on our database on 2017-02-27 and is currently at version 1.
download button
Thank you for downloading from SoftPaz! Your download should start any moment now. It would be great if you could rate and share:
Rate this software:
Share in your network:
features

Korgo Removal Tool Description

Korgo Removal Tool is a lightweight utility that can easily find and eliminate the Win32.Worm.Korgo infection from your system.
The worm exploits the Microsoft LSASS Windows vulnerability for spreading.
Once run, the worm will do the following:
1. Attempts to delete Go.exe from current location
2. Creates the mutexes:
variant A: r10, rocket10
variant B: r10, u2, uterm5
3. Checks if the [HKLM \SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"WinUpdate"] entry exists
If the key exists:
Attempts to delete the registry entry: [HKLM\Software\Microsoft\Wireless\"Server"]
If the key doesnt exist, it attempts to create it:
[HKLM\Software\Microsoft\Wireless\"Server"="1"]
4. Creates a randomly named copy of the worm in %SYSTEM% folder, as ????????.exe where ? may be any letter.
5. Creates the registry entry
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"WinUpdate"="%SYSTEM%\????????.exe"]
in order to run at startup.
6. Executes the copy of the worm and terminates the current process.
7. Starts many threads, and enters an infinite loop, preventing the system from shutting down.
8. Opens ports: 113, 3067, 2041, allowing remote connection and for sending the worm, scans random IP addresses in order to infect unpatched systems.
Also opens port 6667, as it attempts to connect to a list of IRC servers where it listens for commands.
screenshots

Korgo Removal Tool Screenshots

Korgo Removal Tool screenshot 1
similarSimilar Software