SpywareGuide powered by Actiance Security Labs
Search SpywareGuide Database & Site
Home Access the Guide
List of Products List of Companies List of Categories
Tools
X-RayPC
Terms and Definitions
 
Full Name:
IRCBot.06.040 Websearch   Read More
Type: Worm
Also Known as: IRC-Mocbot!MS06-040 (Mcafee). W32.Wargbot (Symantec). Randax
SG Index: 8 [Explain]
Removal tools: List of products that detect/remove/protect against IRCBot.06.040:
  • IM, P2P control, malware prevention and web filtering in single appliance: Unified Security Gateway
  • Category Description: Virus-like program that spreads automatically to other computers by sending itself out by email or by any other means. A program that propagates itself by attacking other machines and copying itself to the affected machine.

    Worms have self-replicating code that travels from machine to machine by various means. A worms first objective is merely propagation. Worms can be destructive depending on what payload they have been given. Worms may replace files, but do not insert themselves into files.
    Comment: IRCbot.06.040 exploits "Windows Server Service Buffer Overflow" MS06-040 against Windows 2000 machines. It creates a service with the display name "Windows Genuine Advantage Registration Service". It opens port 18067 and waits for commands.
       
    Properties:
  •  Allows remote connect
  •  Allows remote control
  •  Installs Through Exploit
  •  Bundles Software
  •  Opens ports
  • Click here to leave feedback for this product

    Recent Modifications
    2012-1-30  HostSeeker Toolbar
    2012-1-13  2000Cracks
    2012-1-13  7AdPower Dialer
    2012-1-13  Absolu-trans
    2012-1-13  AccessPlugin
    2012-1-13  AcidBattery
    2012-1-13  Acidoor
    2012-1-13  Active-X Dialer
    2012-1-13  Adcheat
    2012-1-13  Adh1_sexarea
     
    Company  | Site and Spyware FAQ
    © Copyright 2003-2011, Actiance, Inc. All rights reserved.   Privacy Policy