四級的--January 26, 2004--W32.Novarg.A@mm



贊助商連結


repsol
2004-01-27, 03:07 PM
W32.Novarg.A@mm

http://securityresponse.symantec.com/avcenter/venc/data/[email protected]

大家要注意啊~~

贊助商連結


repsol
2004-01-27, 03:15 PM
The worm will arrive as an attachment with a file extension of .bat, .cmd, .exe, .pif, .scr, or .zip.

透過信件夾檔
夾檔的副檔名有可能是 .bat, .cmd, .exe, .pif, .scr, or .zip

中獎之後....

When the machine gets infected, the worm will set up a backdoor into the system by opening TCP ports 3127 thru 3198. This will potentially allow a hacker to connect to the machine and utilize it as a proxy to gain access to it's network resources.In addition, the backdoor has the ability to download and execute arbitrary files.