Common Tasks

Recent Posts

Community

Email Notifications

Personal Links

Archives

Security Protection - Harry Waldron (CS)

Security Best Practices, Breaking News, & Updates

MS04-011: Korgo.U - Secunia issued a MEDIUM RISK

  This new Korgo variant poses a significant threat for unpatched Windows systems.  

MS04-011: Korgo.U - Secunia issued a MEDIUM RISK
http://secunia.com/virus_information/10254/korgo.u/

The Korgo.U variant was found on June 24th, 2004. It is very similar to the previous Korgo variants, discovered since June 17th. Korgo.U worm spreads throughout the Internet using a vulnerability in Microsoft Windows LSASS. A description of the vulnerability can be found in Microsoft Security Bulletin MS04-011.  It also opens a backdoor that allows unauthorized access to an affected machine. The worm is distributed as a 9,353-byte Win32 executable. When executed, Korgo.V creates a copy of itself in the %System% directory using a randomly-generated filename that is between 5 and 8 characters in length.

Aliases: Korgo.U
W32.Korgo.Q
W32/Korgo.U
W32/Korgo.U.worm
W32/Korgo.worm.v
Win32.Korgo.V
Win32.Korgo.X
Win32/Korgo.X.Worm
Worm.Win32.Padobot.m