for: 1. worm.agobot.gen. c:\windows\system32\s3serv
The way i deleted the virus was to simply rename regedit.exe in the c:\WINDOWS\ folder to a random file name so it wouldn't be recognised by the virus. From there it was simple to remove all traces of s3serv.exe and restart the pc. Then the file which was in the C:\WINDOWS\system32\ directory could simply be deleted. There were 2 other files which had s3serv in the name which could be found using search which i also deleted.
http://www.hostclub.net/forums/showthread.php?s=1a3273efb8ebb185dca091fc323beb47&threadid=10068
spolsv
http://www.sophos.com/virusinfo/analyses/w32agobotcs.html
I need to find a link, and/ or removal instructions for worm Agobot.
A friend of mine who is a newbie has picked up the Worm on her WIN-XP-Pro standalone home PC.
as far as I know all windows updates are in place as well, her AV [free AVG] definitions are current.
she ran Trend housecall after disabling the system restore and it picked up information about the worm but could not clean it.
the following information is relevant...
on start up she gets this message:
worm/Agobot.6.BG. c:\windows\system 32\s.3serv.exe.
housecall gave her the following messages
1. worm.agobot.gen. c:\windows\system32\s3serv
2. worm agobot.A-1. c:\windows\system32\spolsv
I have been to the Sophos website based on warnings about Agobot posted here, but the only IDES I can find require the use of the Sophos AV.
can someone please help with a removal tool/ link and /or instructions as to where to go in Regedt to eliminate the values.
thank you.
david williams

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic