W32.Korgo.A is a worm that attempts to exploit Microsoft LSASS Windows vulnerability, described in Microsoft Security Bulletin MS04-011. It attempts to use random ports like Bobax but due to a programming error it uses port 2041. It also starts an infinite loop to stop system shutdown.
MS04-011: W32.Korgo.A - New Internet worm
http://www.symantec.com/avcenter/venc/data/w32.korgo.a.html
Ports: TCP ports 113, 2041, 3067, 6667, 445
Target of infection: Unpatched machines vulnerable to Microsoft LSASS Windows exploit.