« Attacking Corporate Networks with BlackBerry devices | Main | Microsoft to offer Vista Upgrade Coupons »

Aug15
Oscarbot.KD Worm exploits the Microsoft MS06-040 Vulnerability
PandaLabs reveals the existence of a new variant of the Oscarbot worm, namely Oscarbot.KD, which is the first worm to exploit themicrosoft087kk.jpg recently released Microsoft patch - MS06-040.

 

The main characteristics of the Oscarbot.KD worm variant:

 

- File name: wgareg.exe or wgavm.exe.

- File size: 9,609 bytes (wgareg.exe) or 9,374 bytes (wgavm.exe).

- It is packed with Mew, and its code is encrypted using a 1-byte XOR mask.

 

Oscarbot.KD spreads across network shared resources, instant messaging programs and by exploiting vulnerabilities. It creates a service called wgareg, in order to pass itself off as the Windows Genuine Advantage Registration Service. Once the worm is run, it waits for remote control commands, received via IRC.

 

Sourced by Virus Alerts, by Panda Software


0 Comments/Trackbacks




submit a trackback

TrackBack URL for this entry:

post a comment

Name, Email Address, and URL are not required fields.





Comment Preview

« Attacking Corporate Networks with BlackBerry devices | Main | Microsoft to offer Vista Upgrade Coupons »

Advertise


Related Resources

Advertise Here

sponsored ads



subscribe


Prefer Email?
Subscribe below-

Enter your Email:


Powered by FeedBlitz What's this?

Current News

Support This Blog

business social media

Use these fast growing business social media sites to promote your business, feature your products, spotlight your business leaders, create links, and drive traffic back to your company site, all for free!

BIZZlogos - Add your logo - free link to your site
BIZZphotos - Add photos of your products and people
BIZZprofiles - Submit your profile and build your online visibility
BIZZspotlight - Spotlight your business with free links
BIZZvideos - Videos about businesses, products and business people.
BIZZbites - "Digg" for Business - Submit your articles and posts

know more media network

View Network Map

Network Feed List (OPML)

Know More Media Network
Feed


we support unitus

PRWeb

Influencer



ITechTips is a member of the Know More Media network of business related blogs.

Here are some current headlines from some of our business publications:

ProductivityGoal

CallCenterScript

AdHurl

TheBizofKnowledge

LandingTheDeal

CustomersAreAlways

HealthCareVox

BrainBasedBusiness

TheInsurancePolicy

MarketingBlurb