Works on: Windows 10 | Windows 8.1 | Windows 8 | Windows 7 | Windows 2012 SHA1 Hash: 3a3af50b1acf66da95554e9f06c805d4f88664cf Size: 61.44 KB File Format: exe
Rating: 2.52173913
out of 5
based on 23 user ratings
Downloads: 1305 License: Free
Korgo Removal Tool is a free software by Bitdefender LLC and works on Windows 10, Windows 8.1, Windows 8, Windows 7, Windows 2012.
You can download Korgo Removal Tool which is 61.44 KB in size and belongs to the software category Removal Tools. Korgo Removal Tool was released on 2010-08-06 and last updated on our database on 2017-02-27 and is currently at version 1.
Thank you for downloading from SoftPaz! Your download should start any moment now. It would be great if you could rate and share:
Rate this software:
Share in your network:
Korgo Removal Tool Description
Korgo Removal Tool is a lightweight utility that can easily find and eliminate the Win32.Worm.Korgo infection from your system.
The worm exploits the Microsoft LSASS Windows vulnerability for spreading.
Once run, the worm will do the following:
1. Attempts to delete Go.exe from current location
2. Creates the mutexes:
variant A: r10, rocket10
variant B: r10, u2, uterm5
3. Checks if the [HKLM \SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"WinUpdate"] entry exists
If the key exists:
Attempts to delete the registry entry: [HKLM\Software\Microsoft\Wireless\"Server"]
If the key doesnt exist, it attempts to create it:
[HKLM\Software\Microsoft\Wireless\"Server"="1"]
4. Creates a randomly named copy of the worm in %SYSTEM% folder, as ????????.exe where ? may be any letter.
5. Creates the registry entry
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\"WinUpdate"="%SYSTEM%\????????.exe"]
in order to run at startup.
6. Executes the copy of the worm and terminates the current process.
7. Starts many threads, and enters an infinite loop, preventing the system from shutting down.
8. Opens ports: 113, 3067, 2041, allowing remote connection and for sending the worm, scans random IP addresses in order to infect unpatched systems.
Also opens port 6667, as it attempts to connect to a list of IRC servers where it listens for commands.