Remove Mogi

Posted on February 8th, 2011 in Common Technique by admin

What is Mogi as well as dismissal instructions

Mogi is an Internet worm, that spreads by record pity networks regulating renouned peer-to-peer applications together with eDonkey2000, Kazaa, eMule, Limewire, Morpheus, BearShare as well as Gnucleus. It might additionally generate around the ICQ network.

Once executed, Mogi silently installs itself to the system, hides forsaken files with the rootkit, injects antagonistic formula in to using processes as well as runs the swelling routine. It creates putrescent files with suggestive names in common directories of commissioned record pity programs.

The worm’s cargo is comprised of multiform damaging functions. Mogi terminates using antiviruses, firewalls, security-related programs, compared refurbish collection as well as processes of assorted alternative applications. It installs the rootkit in sequence to disguise the wake up as well as participation in the complement as well as performs Denial of Service attacks opposite predefined remote hosts.

Mogi automatically runs upon each Windows startup.

Mogi primer removal:
Kill processes:
ath.exe, bayloz.exe, bomba.exe, bonk.exe, dragon_naturallyspeaking_xp.exe, jolt2.exe, iexplore.exe, kod.exe, layer.exe, multi_password_cracker.exe, norton_2004_setup.exe, sin.exe, smurf.exe, suf.exe, syn.exe
Delete registry values:
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunservices=iexplore.exe
Delete files:
ath.exe, bayloz.exe, bomba.exe, bonk.exe, dragon_naturallyspeaking_xp.exe, jolt2.exe, iexplore.exe, kod.exe, layer.exe, multi_password_cracker.exe, norton_2004_setup.exe, sin.exe, smurf.exe, suf.exe, syn.exe, covert.dll
Misc:
The covert.dll record is the rootkit. Disabling it unhides alternative Mogi files.
Files dragon_naturallyspeaking_xp.exe, norton_2004_setup.exe as well as multi_password_cracker.exe have been distributed by record pity networks. Do not download as well as govern them!

Exact record location:
dragon_naturallyspeaking_xp.exe, norton_2004_setup.exe, multi_password_cracker.exe – common folders of commissioned peer-to-peer applications
other files – C:WindowsSystem, C:WindowsSystem32 or C:WinntSystem32


Article Source: レジストリクリーナー

Post a comment