|
|
Virus Warning: W32.Gaobot.YC
2004-04-07
W32.Gaobot.YC is a variant of W32.HLLW.Gaobot.gen that attempts to spread to network shares and allows access to an infected computer through an IRC channel.
The worm uses multiple vulnerabilities to spread, including:
- The DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026), using TCP port 135
- The RPC locator vulnerability (described in Microsoft Security Bulletin MS03-001), using TCP port 445
- The WebDav vulnerability (described in Microsoft Security Bulletin MS03-007), using TCP port 80
W32.Gaobot.YC is packed with UPX and IHMOWrap3.
A removal tool is available at http://www.symantec.com.
|