Michael Evans
2007-08-09, 01:49
When I use either of my portable disk drives to place back my saved
files and folders to my factory recovered PC, Spybot 1.4 and now Spybot 1.5
reports a blank start up entry and refers to the entry as Agobot-KU worm.
This has happened on four computers (XP home and XP Pro) and now on my new
HP Pavillion with Vista.
I have recovered Vista and have not loaded any files from an external source.
If the Agobot-KU worm comes from my external flash and/or my portable hard drive,
what do I do?
Is it possible to get all the files and folders that I must have without getting the worm?
Also, Trendco HiJack This 2.0 reports; (Before any internet visits)
That my HP with Vista has a
01 hijack entry, (auto.search.msn), and
013 hijack, (Gopher Prefix; regarding URL hijacks, and
changed hosts file with a added entry of ":1 localhost" on the line
under 127.0.0.1 localhosts line as listed below.
I deleted the 01 and 013 entries
127.0.0.1 localhosts
:1 localhosts
HiJack This changes the above entries to;
127.0.0.1 localhosts
#:1 localhosts
Then I immunized my system with Spybot.
Spybot S & D 1.5 then lists the over immunized 50,000 items next.
I have searched this forum and others, but can not find a solution to get rid of the
Agobot KU worm.
Can anyone please help me?
fyi: I PM'ed this link to this member:
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
If it helps
files and folders to my factory recovered PC, Spybot 1.4 and now Spybot 1.5
reports a blank start up entry and refers to the entry as Agobot-KU worm.
This has happened on four computers (XP home and XP Pro) and now on my new
HP Pavillion with Vista.
I have recovered Vista and have not loaded any files from an external source.
If the Agobot-KU worm comes from my external flash and/or my portable hard drive,
what do I do?
Is it possible to get all the files and folders that I must have without getting the worm?
Also, Trendco HiJack This 2.0 reports; (Before any internet visits)
That my HP with Vista has a
01 hijack entry, (auto.search.msn), and
013 hijack, (Gopher Prefix; regarding URL hijacks, and
changed hosts file with a added entry of ":1 localhost" on the line
under 127.0.0.1 localhosts line as listed below.
I deleted the 01 and 013 entries
127.0.0.1 localhosts
:1 localhosts
HiJack This changes the above entries to;
127.0.0.1 localhosts
#:1 localhosts
Then I immunized my system with Spybot.
Spybot S & D 1.5 then lists the over immunized 50,000 items next.
I have searched this forum and others, but can not find a solution to get rid of the
Agobot KU worm.
Can anyone please help me?
fyi: I PM'ed this link to this member:
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
If it helps