|
||
9/22: Agobot-XJ Worm Exploits Mic Flaws Worm_Agobot.XJ is a memory-resident worm that is another variant of the AGOBOT family that exploits several Microsoft vulnerabilities. They are discussed in the following pages:
It can also use the backdoor capabilities of some malware to propagate into accessible systems.
This worm propagates through network shares, and drops a copy of itself as SYSCONF.EXE in the Windows system folder. It uses a list of user names and passwords to gain access to shared folders.
It acts as a server program controlled by an Internet Relay Chat (IRC) bot, thus capable of certain backdoor activities. It is also capable of stealing the CD keys of popular Windows-based applications and terminating certain programs. This worm also is capable of launching denial of service (DDoS) attacks.
It runs on Windows NT, 2000 and XP.
Technical details are at Trend Micro page.
|
||
|