Search:       

Tuesday, 7 October 2008       

Worm.Win32.Padobo Spyware/Adware Definition


Name: Worm.Win32.Padobo
Category: Viruses
Description: Details
Worm.Win32.Padobot

Worm.Win32.Padobot.a (also known as Korgo) spreads throughout the Internet using a vulnerability in Microsoft Windows LSASS. A description of the vulnerability can be found in Microsoft Security Bulletin MS04-011
The worm is written in C++ and is approximately 10KB in size, packed using UPX.
Propagation
When launching, the worm copies itself to the Windows system directory under a random name, and registers this file in the system registry auto-run key:
[HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun]
WinUpdate = %system%name of file
It also creates a registry key
HKLMSOFTWAREMicrosoftWireless
Server = 1
It creates the mutexes "10", "u2" and "uterm5" to flag its presence in the system.
The worm chooses the IP-addresses of random machines to infect and attack, similar to other worms which exploit the same LSASS vulnerability.
Other
Once infected, a victim machine will display an error message that the LSASS service has failed. After this error message has been displayed, the computer may reboot.
The worm open TCP ports 113, 3067 and 2041 to receive commands.
It attempts to connect to several IRC channels:
moscow-advokat.ru
graz.at.eu.undernet.org
flanders.be.eu.undernet.org
caen.fr.eu.undernet.org
brussels.be.eu.undernet.org
los-angeles.ca.us.undernet.org
washington.dc.us.undernet.org
london.uk.eu.undernet.org
lia.zanet.net
gaspode.zanet.org.za
irc.kar.net
to receive commands and transmit data.


Top Viruses Visited Pages:
Macro.Word.Ord
Parity.44
Pathhunt.123
Perfume Famil
Permutan.54
Phantasmagori
Pieck.201
Ply.422
PME.Burglar.326
Poem.182
Polifemo Famil
Populizer Famil
Potpis.69
Predator.115
PrintDevil.71

 


Main Menu
Home
Top Downloads
New Programs
Awards
Submit
Link to us
Spyware Definitions
Viruses Info
Recipes
Jokes
Contact us




 

 

- Privacy Policy -