It carries out actions that decrease the security level of the computer.

Affected platforms: Windows 2003/XP/2000/NT/ME/98/95First detected on:Jan. 2, 2007Detection updated on:June 18, 2010StatisticsNoProactive protection:Yes, using TruPrevent Technologies Brief Description     Gaobot.OXI is a worm that spreads by copying itself, without infecting other files. It captures It does this by injecting code into the "avserve.exe" process, so that when the Sasser worm attempts to propagate, it sends Gaobot to the remote system instead of Sasser. By now, your computer should be completely free of W32/CubsPewt.worm infection. WORM_AGOBOT.GEN ...gen (Kaspersky); W32.HLLW.Gaobot (Symantec); W32/Gaobot.worm.gen.j (McAfee); W32/Agobot-Gen (Sophos...Ikarus); a variant of Win32/Agobot trojan (Eset); W32/Gaobot.gen.worm (Panda); WORM_AGOBOT.FS Alias:Win32/HLLW.Gaobot, W32/Gaobot.worm.gen.g, W32.HLLW.Gaobot.gen, Backdoor.Win32.SdBot.14672, Worm/Agobot.PD, W32/Gaobot.NU.worm, MS03-026 Exploit.Trojan, Backdoor... https://forums.techguy.org/threads/w32-gaobot-oxi-worm.877125/

A W32/CubsPewt.worm infection can be as harmless as showing annoying messages on your screen, or as vicious as disabling your computer altogether.

Indication of Infection This symptoms of this detection are the files, registry, and network communication referenced in the characteristics section. Worm:Win32/Gaobot (Microsoft); W32/Gaobot.worm.gen.d (McAfee); W32.HLLW.Gaobot.gen (Symantec); Backdoor.Win32.Agobot.afr (Kaspersky)

It uses anti-monitoring techniques in order to prevent it being detected by antivirus companies. As of this writing, the server is unavailable. The worm uses social engineering (such as an enticing file name) that might invite a user on another computer to download and run the worm.   Computers connected to a local area http://www.trendmicro.com/vinfo/us/threat-encyclopedia/search/w32.gaobot Set up a TFTP server or an HTTPD server.

To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner.

Workstation Service Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-049) using TCP port 445. ActivitiesRisk LevelsEnumerates many system files and directories.Adds or modifies Internet Explorer cookiesNo digital signature is present

WORM_RBOT.AHZ Alias:Backdoor.Win32.Rbot.bgw (Kaspersky), W32/Gaobot.worm.gen.e (McAfee), W32.Spybot.Worm (Symantec), Worm/Rbot.368128 (Avira), Mal/Behav-053 (Sophos)

Windows XP users are protected against this vulnerability if Microsoft Security Bulletin MS03-043 has been applied. Additional information Worm:Win32/IRCbot.B opens the browser to the following URL in an attempt to distract the user while it performs its malicious routines:   http://browseusers.myspace.com/Browse/Browse.aspx   Analysis by Andrei Florin Saygo Download and run files.

To exploit them successfully it needs the intervention of the user: opening files, viewing malicious web pages, reading emails, etc. Via Internet, exploiting remote vulnerabilities: attacking random IP addresses, in which it tries to insert a copy of itself by exploiting one or more vulnerabilities.IRC: It sends a copy of itself

After copying itself to either folder, the worm modifies the registry to execute the worm copy at each Windows start.

Worm:Win32/IRCbot.B is a worm that may spread to other computers by sending a link to itself to a user's contact on Yahoo! WORM_GAOBOT.AC Alias:W32.HLLW.Gaobot.AA, W32/Gaobot.worm.gen.b, W32/Agobot.AV, Win32.HLLW.Agobot.11, W32/Gaobot.U.worm