Home Malware Programs Worms Net-Worm.Win32.Padobot.ag

Net-Worm.Win32.Padobot.ag

Posted: August 2, 2011

Net-Worm.Win32.Padobot.ag is a years-old worm that compromises your computer's security to open the system up to other attacks, including malware installation or criminal remote control. Like many worms, such as Net-Worm.Win32.Koobface.iap and Worm.Win32.Agent.adz, Net-Worm.Win32.Padobot.ag is also capable of installing itself automatically over networks and will create copies of itself for this purpose. Since SpywareRemove.com malware analysts have found Net-Worm.Win32.Padobot.ag to create multiple vulnerabilities on an infected computer, you should deal with Net-Worm.Win32.Padobot.ag as a high-level threat and remove Net-Worm.Win32.Padobot.ag infections with a powerful anti-malware application.

Clamping Down on Net-Worm.Win32.Padobot.ag's Duplicates Before They Get to You

Network security should be a top concern for anyone who's worried about Net-Worm.Win32.Padobot.ag infections. You can detect potential infections by noticing altered port settings, especially open ports (usually, only a very restricted amount of ports, preferably those that are used on a regular basis for network activity, should be open). Net-Worm.Win32.Padobot.ag will open dozens of TCP ports to allow itself to contact remote servers freely; however, this malicious behavior also makes it easy to catch Net-Worm.Win32.Padobot.ag if you're watching your port settings.

SpywareRemove.com research team has also found that Net-Worm.Win32.Padobot.ag can reproduce via networks by using the same techniques that are common to many other worms. Net-Worm.Win32.Padobot.ag copies its body to a network-shared folder, hides these files (typically by using the System or Hidden attributes) and then adds on an Autorun.inf file. Together, these actions let Net-Worm.Win32.Padobot.ag infect any PC that accesses the same folder; this attack doesn't require consent or even visible activity.

Net-Worm.Win32.Padobot.ag will launch itself by default whenever Windows launches, so you should assume that Net-Worm.Win32.Padobot.ag is active unless you've taken measures to avoid this. The ideal way of stopping Net-Worm.Win32.Padobot.ag's launch is to use Safe Mode, although more extreme measures may be required in some cases.

What to Be Aware of While Net-Worm.Win32.Padobot.ag is Still Around

SpywareRemove.com malware researchers have found that Net-Worm.Win32.Padobot.ag is strongly reminiscent in behavior to Net-Worm.Win32.Padobot.m, including using the same Lsass exploit that its cousin is known to exploit. Other risks that may involve Net-Worm.Win32.Padobot.ag infection can include:

  • Security settings that are altered without your consent, usually to make the computer malleable to additional attacks.
  • Disabled programs, including basic tools like Task Manager and advance threat-removal program.
  • Unusual network traffic that degrades your computer's performance and uses up RAM and other system resources.
  • The installation of other malicious programs, such as keyloggers, Trojans or scamware.
  • Remote control of your PC (often administered with the help of RATs or Remote Administration Tools). Remote-based attacks may steal passwords and other sensitive information, damage your PC or control your computer's actions outright.

As a very serious security threat, Net-Worm.Win32.Padobot.ag should be deleted at the first opportunity. Since finding all copies of Net-Worm.Win32.Padobot.ag or other worm infections is difficult, you should consider using an anti-malware program to detect and remove Net-Worm.Win32.Padobot.ag.

Loading...