Add a computer worm taking advantage of the error MS06-040
Yesterday, Symatec warned of a new computer worm targeting the security bug MS06-040 that appeared on the Internet.
The new computer worm - named " Randex.gel " - belongs to the ' network-ware ' computer worm line. The network-ware worm is a worm that can be remotely controlled via IRC (Internet Rely Chat) channels and automatically scans the internal network for infection. Therefore, the main function of the worm Randex.gel is to open a back door on infected systems to wait for the control command from their 'owner' via IRC channel.
Oliver Friedrichs - Symantec's director of security response group - said this could be a variant of the Randex worm. The only difference with that computer worm line is Randex.gel that can exploit the security bug MS06-040.
Previous variations of the Randex worm line targeted other security vulnerabilities in Windows such as MS04-007, MS05-017, and MS05-039 - these errors have been fixed by Microsoft.
Friedrichs stated that the code that plays the role of exploiting security bugs mainly in the depth of Randex.gel is very different from other variants. In fact, this code is very similar to the code of HD Moore security researcher released two weeks ago.
Symantec said the Randex worm could spread in a lot of different ways like through MSN Messenger, AOL Instant Messenger, Yahoo Messenger, and ICQ. The Randex.gel worm can also be distributed through Microsoft SQL servers. If the Randex.gel worm finds a SQL server, it will immediately infect all databases located on that server.
Another function of the worm Randex.gel is to steal personal account information of eGold electronic payment service users when users log into egold.com website.
Although there are many such malicious functions, the Randex.gel worm cannot cause much damage because Microsoft has released the above security patch update.
Hoang Dung
You should read it
- Deep new computer: unexpectedly simple?
- The new worm attacked AIM and caused heavy damage
- Will the Kama Sutra worm come back next week?
- Koobface worm exploded in the Christmas season
- There are worms to fake Microsoft patches again
- Nugache threatened the throne of Storm
- New depths appear to attack Nokia phones
- D32 Virus Removal Software updates new viruses on December 25, 2004
May be interested
- Will the Kama Sutra worm come back next week?security experts are now warning users around the world to protect themselves from the ability to return to the new dangerous computer worm kama sutra next week. kama sutra worm - also known as nyxe worm
- Deep new computer: unexpectedly simple?security companies have just warned of a new worm worm spreading strongly on the internet.
- Open a virtual Valentine card, really deepvalentine's day e-cards don't seem as sweet as you might think, especially when it comes from a stranger. according to the latest fbi recommendations, a deep wave, viruses and trojans are rising strongly, taking advantage of valentine's day to help
- Storm worm takes advantage of earthquake disaster in Chinaif you want to read information about the shocking earthquake in sichuan last month, it's best to visit an official press website.
- 'Happy New Year' worm is spreading stronglyduring the transfer days between the old year and the new year, hackers have released a computer worm (worm) that spreads very fast, by hitting the user's psychology when placing dispersal emails. deep n & a
- Conficker worm still silently growsaccording to the conficker worm team wrote on trend micro's security blog, the dangerous computer worm conficker has many new variants.
- Storm worm 're-exported' through a jokedangerous computer worms storm worm used to scan millions of computers and social networks. its variant is continuing to attack by email bearing the april fool's day theme.
- The new worm attacked AIM and caused heavy damagea security company has just warned of a new computer worm that is spreading strongly through aol's aim instant messaging application and causes more damage than imagined.
- Serious security flaws on Windows 10 allow anyone to log in by voiceon windows 10, there is a new bug called open sesame (open), taking advantage of this error, hackers can use their own voice to execute code at any time on the computer.
- Even without a penny, don't think about taking advantage of these 5 peoplethose who lend you money mean that they have sent your love to you, so don't play tricky or take advantage of anyone's kindness, especially those below.