|
Sunday, 03 September 2006 |
W32/Opanki.worm!MS06-040 is a worm that also drops a rootkit component to hide its files and processes. This rootkit component is detected as NTRootKit-J.
The worm can spread over AIM instant messenging, opens a backdoor at TCP port 443 and tries to connect to IRC server and waits for commands. One of the ways this worm can spread is by exploiting Server Service Vulnerability (MS06-040) and older vulnerabilities including a buffer overflow in the Workstation Service (MS03-049). Aliases
* Backdoor.Win32.Rbot.ayg (Kaspersky)
* WORM_RBOT.AEY (TrendMicro) |