Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

WORM_RXBOT.CK

BugsAlert Home > WORM_RXBOT.CK
 
 

This worm may arrive via network shares. It may also be downloaded unknowingly by a user when visiting malicious Web sites.

It drops files and creates registry entries to enable its automatic execution at every system startup. It modifies registry entries as part of its installation routine.

This worm opens a random port to allow a remote user to connect to the affected system. Once a successful connection is established, the remote user executes commands on the affected system.




Original Source: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_RXBOT.CK

Learn more about WORM_RXBOT.CK
 
Tags: worm rxbot.ck

Related Items

      VMWare's VMSafe: Security Industry Defibrilator

      VU#120593:Meridian Prolog Manager uses weak authentication to store and transmit user credentials

      FrSIRT - Debian Security Update Fixes Squid Cache Update Reply DoS Issue

      CVE-2007-6040 (F5D7230-4)

      Netembryo "Url_init()" Denial of Service Vulnerability

      CVE-2008-2020 (PHP-Nuke, e-Commerce-Suite, phpMyBitTorrent, TorrentFlux, e107, WebZE, OpenDb, La...)

      Fedora 8 Update: setroubleshoot-2.0.5-2.fc8

 

Pixel