Home  l  Role & Plan  l  News & Updates  l  Policies  l  Helpdesk  l  Sections  l  Asset Systems  l  Location  l  Cisco Academy  l  
USP Home » Information Technology Services » Helpdesk » Computer Security Defences » W32/Korgo.x worm

Print

.

|

.

» Services
» Student Support
» Computer Guides
» USP Computer Standards
» Online Forms
» FAQ
» Computer Security Defences
Virus FAQ
Installing Windows Updates
Running Windows Security Patches
W32/Korgo.x worm
W32/Bagle.az@MM worm
Running Spybot
Running Stinger
Scanning your PC for Virus
» Software Downloads
» Training

Quick Links
» Services
» Student Labs
» Computer Guides
» Online Forms
» Security Tips
» Telephone Guides




W32/Korgo.x worm

Name of virus: W32.Korgo worm

Type of virus: WormSystems

Systems Affected: Windows 2000/XP

What does it do?

W32.Korgo.X variant is a worm that attempts to propagate byexploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability onTCP port 445. This self- executing worm spreads by exploiting this Microsoft Windows vulnerability:MS04-011 vulnerability (CAN-2003-0533) http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx

The worm spreads with a random filename and acts as a remote access server to allow an attacker to control the compromised system. This variant also attempts to download and execute a file from a remote Website.

Removal Instructions:

1.  You need to download the latest Stinger utility from our public domain on \\nas2\publicsw. Stinger is a stand-alone utility used to detect and remove specific viruses. The current Stinger utility version 2.3.0.0 which was built on 5 July 2004 should be able to remove W32.Korgo variants. It is not a substitute for full anti-virus protection, but rather a tool to assist administrators and users when dealing with an infected system.

2.  Click here for instructions on Running Stinger.

For our Centre users, you can contact your IT personnel for assistance. If you have any difficulties, please contact our Helpdesk on Ext 2117.


Disclaimer & Copyright l Contact Us l 
© Copyright 2004 - 2005. All Rights Reserved.
Page updated: Monday, January 24, 2005
Information Technology Services
The University of the South Pacific
Laucala Campus, Suva, Fiji
Tel: +679 323 2117