W32.Korgo.I
| Discovered on: June 07, 2004 Description:
W32.Korgo.I is a variant of W32.Korgo.F. This worm attempts to propagate
by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability
(described in Microsoft
Security Bulletin MS04-011) on TCP port 445. It also listens on TCP
ports 113, 3067, and other random ports (256-8191).
Removal Instructions For Symantec & Norton Users:
- Disable System Restore (Windows Me/XP).
- Update the virus definitions.
- Restart the computer in Safe mode or VGA mode.
- Run a full system scan and delete all the files detected as
W32.Korgo.I.
- Reverse the changes made to the registry.
|
| |
|
Our
Staff Recommends
 
|
Top
Ranked Software for Anti-Virus,
Spyware, Firewall,
Adware
Remover and everything else for software.
I
Warned You - Software and Computer Protection
 
|