Home Malware Programs Worms Net-Worm.Korgo

Net-Worm.Korgo

Posted: June 3, 2010

Threat Metric

Ranking: 3,275
Threat Level: 9/10
Infected PCs: 55,360
First Seen: July 24, 2009
Last Seen: March 8, 2025
OS(es) Affected: Windows

Net-Worm.Korgo is a network-aware Worm that uses known exploits to replicate across vulnerable networks. Net-Worm.Korgo opens a conduit to welcome a host of malware onto the infected system. Net-Worm.Korgo poses a serious threat to PC security and can cause loss of sensitive data or other faults such as slow system performance. Victims are advised to use a reliable security application to terminate Net-Worm.Korgo immediately.

Aliases

Trj/Passtealer.FZ [Panda]Worm/Delf.GOD [AVG]W32/AutoRun.LW!worm [Fortinet]Win-Trojan/Autorun.59392.B [AhnLab-V3]W32/SillyFDC-BP [Sophos]TR/Agent.AGBR [AntiVir]Win32.HLLW.Autoruner.1773 [DrWeb]Worm.Win32.AutoRun.EY [Comodo]Trojan.Agent.AGBR [BitDefender]Worm.Win32.AutoRun.lw [Kaspersky]Trojan.Autorun-220 [ClamAV]Win32:AutoRun-QM [Wrm] [Avast]W32/Worm.AXFI [F-Prot]Win32/AutoRun.EY [NOD32]W32/Autorun.worm.r [McAfee]
More aliases (2804)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\documents\database.mdb File name: database.mdb
Size: 8.43 KB (8432 bytes)
MD5: 0a456ffff1d3fd522457c187ebcf41e4
Detection count: 6,326
Mime Type: unknown/mdb
Path: %SYSTEMDRIVE%\Users\<username>\documents
Group: Malware file
Last Updated: September 1, 2024
D:\doc01 .scr File name: doc01 .scr
Size: 114.68 KB (114688 bytes)
MD5: d3dd17b567bdc7e7daa1ab36495d1bcb
Detection count: 92
Mime Type: unknown/scr
Path: D:
Group: Malware file
Last Updated: October 5, 2017
naked.exe File name: naked.exe
Size: 73.73 KB (73732 bytes)
MD5: da4371bc7347d3633c0eea308c9cb444
Detection count: 90
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%ALLUSERSPROFILE%\Adobe .scr File name: Adobe .scr
Size: 200.7 KB (200704 bytes)
MD5: 4798cecc36d9952ba73633c54f3468b6
Detection count: 77
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: October 5, 2017
D:\LAPTOP DATA .scr File name: LAPTOP DATA .scr
Size: 47.61 KB (47612 bytes)
MD5: 349752fc724199059603073bacfa429e
Detection count: 74
Mime Type: unknown/scr
Path: D:
Group: Malware file
Last Updated: October 5, 2017
%ALLUSERSPROFILE%\Application Data .scr File name: Application Data .scr
Size: 1.23 MB (1232896 bytes)
MD5: 3c59bd20783744e16f749127055b52de
Detection count: 74
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: October 5, 2017
gip3.exe File name: gip3.exe
Size: 82.84 KB (82848 bytes)
MD5: 644814aa418a3ae1716daa7fb484a539
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
gip1.exe File name: gip1.exe
Size: 45.05 KB (45056 bytes)
MD5: dbea1cc228c9353851e06599788a5a5e
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%SystemDrive%\FOUND.039 .scr File name: FOUND.039 .scr
Size: 118.78 KB (118784 bytes)
MD5: e64e104bd27c0e0c7eb7d1b528f45b06
Detection count: 56
Mime Type: unknown/scr
Path: %SystemDrive%
Group: Malware file
Last Updated: October 5, 2017
%ALLUSERSPROFILE%\InstallMate .scr File name: InstallMate .scr
Size: 204.8 KB (204800 bytes)
MD5: 9b85d177c939421dc4a4e7f3bee729a2
Detection count: 46
Mime Type: unknown/scr
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: October 5, 2017
K:\kop .scr File name: kop .scr
Size: 40.96 KB (40960 bytes)
MD5: 7a0b5674ec20b6455559ca1d70dc2c55
Detection count: 44
Mime Type: unknown/scr
Path: K:
Group: Malware file
Last Updated: October 5, 2017
E:\Folder 02\VirusShare_15c2f7ece2c6647c5e45608e39b08e34 File name: VirusShare_15c2f7ece2c6647c5e45608e39b08e34
Size: 40.96 KB (40960 bytes)
MD5: 15c2f7ece2c6647c5e45608e39b08e34
Detection count: 41
Path: E:\Folder 02\VirusShare_15c2f7ece2c6647c5e45608e39b08e34
Group: Malware file
Last Updated: January 10, 2022
C:\Users\<username>\Desktop\The-MALWARE-Repo-master\Email-Worm\Prolin.exe File name: Prolin.exe
Size: 36.86 KB (36864 bytes)
MD5: 65eeb8a0fce412d7f236f8348357d1c0
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\The-MALWARE-Repo-master\Email-Worm\Prolin.exe
Group: Malware file
Last Updated: January 27, 2025
paukor.exe File name: paukor.exe
Size: 416.25 KB (416256 bytes)
MD5: 7e20359dfc0b2291487f1a45c4471988
Detection count: 34
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
C:\Projects\Dr.Web\Virii\!!!vir\MAR\W32NAKED\NAKEDWIF.EXE File name: NAKEDWIF.EXE
Size: 73.72 KB (73728 bytes)
MD5: da9dba70de70dc43d6535f2975cec68d
Detection count: 33
File type: Executable File
Mime Type: unknown/EXE
Path: C:\Projects\Dr.Web\Virii\!!!vir\MAR\W32NAKED\NAKEDWIF.EXE
Group: Malware file
Last Updated: January 27, 2025
fintas.exe File name: fintas.exe
Size: 36.86 KB (36864 bytes)
MD5: 42b1eb959ce76f9013e8e9922305ca29
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2022
%USERPROFILE%\Desktop\????\عععع .scr File name: عععع .scr
Size: 76.28 KB (76284 bytes)
MD5: 7ab70d44ec07d076ea7dc7e8aff6a011
Detection count: 22
Mime Type: unknown/scr
Path: %USERPROFILE%\Desktop\????
Group: Malware file
Last Updated: October 5, 2017
toil.exe File name: toil.exe
Size: 8.19 KB (8192 bytes)
MD5: ec8a1659c7d67a3859d515130bae3c4c
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 11, 2020
%USERPROFILE%\Desktop\111\ADORER AVEC NOUS .scr File name: ADORER AVEC NOUS .scr
Size: 3.37 MB (3373568 bytes)
MD5: 5421ad3e8fbe0f8a04e617224f4abbf0
Detection count: 5
Mime Type: unknown/scr
Path: %USERPROFILE%\Desktop\111
Group: Malware file
Last Updated: October 5, 2017
E:\New folder\VirusShare_2ca27551e11bf054f7c5cb98eac11408 File name: VirusShare_2ca27551e11bf054f7c5cb98eac11408
Size: 36.86 KB (36864 bytes)
MD5: 2ca27551e11bf054f7c5cb98eac11408
Detection count: 5
Path: E:\New folder\VirusShare_2ca27551e11bf054f7c5cb98eac11408
Group: Malware file
Last Updated: January 20, 2022
magistr.exe File name: magistr.exe
Size: 77.82 KB (77824 bytes)
MD5: a8cfcfa06303168b5f94e0696882a3c8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 24, 2021
E:\Folder 02\VirusShare_0eb3cca824da735aa040caa012450748 File name: VirusShare_0eb3cca824da735aa040caa012450748
Size: 76.8 KB (76800 bytes)
MD5: 0eb3cca824da735aa040caa012450748
Detection count: 5
Path: E:\Folder 02\VirusShare_0eb3cca824da735aa040caa012450748
Group: Malware file
Last Updated: January 20, 2022

More files

Registry Modifications

The following newly produced Registry Values are:

File name without path! My Picutre.SCR!new.scrimages.scrNew Folder.exeThumbs .dbwindows vista setup .scrRegexp file mask%ALLUSERSPROFILE%\Adobe .scr%APPDATA%\Microsoft\winlog.exe%APPDATA%\MusaLLaT.exe%APPDATA%\readere_lm.com%SystemRoot%\System32\XP-[RANDOM CHARACTERS].exe%WINDIR%\dc.exe

Additional Information

The following directories were created:
%PROGRAMFILES%\windows common files%PROGRAMFILES(x86)%\windows common files%TEMP%\E_4%TEMP%\E_N4
Loading...