Big Yellow worm - Exploits SAV update vulnerability if unpatched
A second round of the SAV worm is circulated on unpatched Symantec PCs (vulnerable to the buffer overflow exploit)
Big Yellow worm - Exploits SAV update vulnerability if unpatched
http://www.incidents.org/diary.php?storyid=1945
http://research.eeye.com/html/alerts/AL20061215.html
QUOTE: This file was being downloaded by a large number of machines that were recently exploited using the SAV remote exploit. The sequence of events for these compromises were:
1. Exploit comes in from an IP address
2. Stops the Windows firewall service,
3. Creates an ftp command script named "x" which is later run by ftp.exe -s:x
4. which downloads NL.eXe
5. May include keylogger
SOLUTION: Users need to apply the SYM06-010 patch
Symantec Client Security and Symantec AntiVirus Elevation of Privilege
http://www.symantec.com/avcenter/security/Content/2006.05.25.html