Selected viruses, spyware, and other threats: sorted alphabetically
Short descriptionWin32/Agent.NEG is a worm that spreads by copying itself into the root folders of available drives. The worm contains a backdoor. It can be controlled remotely.
InstallationWhen executed, the worm copies itself into the following location:
- %system%sysinfo.exe (61440 B)
- Windows netware work information system setup
"Type" = 272
"Start" = 2
"ErrorControl" = 1
"ImagePath" = "%system%sysinfo.exe"
"DisplayName" = "Windows netware work information system setup"
"ObjectName" = "LocalSystem"
"Description" = "Provide security by Windows netware work system information"
SpreadingThe worm copies itself into the root folders of all drives using the following filename:
The name of the file may be based on the name of an existing file or folder.
Other informationThe worm acquires data and commands from a remote computer or the Internet. It uses its own P2P network for communication.
It can execute the following operations:
- send files to a remote computer
- run executable files
- download files from a remote computer and/or the Internet
- delete folders
- delete files