PDA

Visualizza versione completa : Worm-Backdoor.WNT/Agobot.AV@RPC - Rischio 4 - Update


Giorgius
26-11-2003, 18.55.27
Ennesima variante di questo Worm.

Aliases:
W32.HLLW.Gaobot.gen, Win32.HLLW.Agobot, Worm/Agobot, Worm-Backdoor.WNT/Agobot.AV@RPC, W32/Gaobot.gen

Effetti:
This memory–resident malware has both worm and backdoor capabilities.
Like earlier AGOBOT variants, this worm also exploits the following Windows vulnerabilities to propagate across the network:
Remote Procedure Call (RPC) Distributed Component Object Model (DCOM) vulnerability on Windows 2000 and XP
RPC locator vulnerability on Windows NT, 2000, and XP
Buffer Overrun vulnerability in IIS 5.0/WebDav

Info:
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AGOBOT.AV
http://www.alerta-antivirus.es/virus/detalle_virus.html?cod=3300&PHPSESSID=c9db0a3e35d0a1cb858cf6c68ec68708
http://www.pandasoftware.com/virus_info/encyclopedia/overview.aspx?idvirus=40759


Aggiornamento AntiVirus al 26.11.03 ;)(Y)

Giorgius
26-11-2003, 19.21.10
http://www.pandasoftware.com/products/activescan/