Store Locator: Enter Zip Code: List All Locations

W32.Korgo.F variant worm hassling users on the Internet!

Question

W32.Korgo.F is one of the more spread variant worms hassling users on the Internet.

Answer

This question was answered on June 4, 2004. Much of the information contained herein may have changed since posting.

The threat level for W32.Korgo.F (A.K.A. Kaspersky), found on June 1st, has already been upgraded to a Category 3 on the SARC site. This new threat has backdoor functionality that allows unauthorized access to networks. The worm attempts to propagate by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability on TCP port 445. It also listens on TCP ports 113, 3067, 6667 and other random ports.

The primary symptoms for infected machines include the inability to shutdown or reboot the system and a performance decrease. Microsoft Windows 2000 & XP are the only operating systems affected by this wild worm. The security hole, known as the LSASS vulnerability, is the same vulnerability the Sasser worm attacked. Sophos experts have advised computer users that there is no need to panic about the family of worms known as Korgo, because if you updated to protect against Sasser then you have already sealed up the vulnerability.

FOR THE TECHNICALLY INCLINED:

If you have a system that is already infected by this worm, then download the removal tool at: http://securityresponse.symantec.com/avcenter/venc/data/w32.korgo.f.removal.tool.html

For optimal security it is suggested that you update your Microsoft & anti-virus software, You can get more technical information about this outbreak & removal instructions at:

<a href="http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx"> http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx</a>

<a href="http://www.sarc.com/avcenter/venc/data/w32.korgo.f.html"> http://www.sarc.com/avcenter/venc/data/w32.korgo.f.html</a>

FOR THOSE NOT TECHNICALLY INCLINED -

Contact your nearest Data Doctors location for service:

http://datadoctors.com/contact/

Author

Posted by Michal of Data Doctors on June 4, 2004

Personal Services | Business Services | Radio Show | Free Help Center | Franchising | About Us | Sitemap

Business Network Solutions | Computer Data Recovery | Computer Franchises | Computer Hardware Repair | Computer Help | Computer Network Support | Computer Problems | Computer Repair | Computer Troubleshooting | Data Recovery | Data Recovery Service | Data Recovery Services | Disk Recovery | File Recovery | Wireless Networking Solutions