Selected viruses, spyware, and other threats: sorted alphabetically
Short description
The worm connects to the IRC network. It can be controlled remotely. It connects to remote machines to port TCP 445 in attempt to exploit the LSASS vulnerability. Installation
When executed, the worm copies itself in the %system% folder using a random filename. The filename has the following extension: - .exe
- go.exe
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run]
"WinUpdate" = "%system%\%variable%.exe
The following Registry entry is set:
- [HKEY_LOCAL_MACHINE\Software\Microsoft\Wireless]
"Server" = 1
Spreading
The worm opens some TCP ports: - 113
- 2041
- 3067
If successful, the remote computer attempts to connect to the infected computer and download a copy of the worm .
This vulnerability is described in Microsoft Security Bulletin MS04-011 .
Other information
The worm connects to the IRC network. It can be controlled remotely. The worm connects to the following addresses:
- moscow-advokat.ru (TCP:6667)
- graz.at.eu.undernet.org (TCP:6667)
- flanders.be.eu.undernet.org (TCP:6667)
- caen.fr.eu.undernet.org (TCP:6667)
- brussels.be.eu.undernet.org (TCP:6667)
