Forum Moderators: open

Message Too Old, No Replies

Windows security threat!

.... again

         

creative craig

5:13 pm on Mar 10, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Heres another one :)

[theregister.co.uk...]

Craig

Brett_Tabke

4:46 am on Mar 11, 2003 (gmt 0)

WebmasterWorld Administrator 10+ Year Member Top Contributors Of The Month



If a successful connection is made, Deloder drops a called INST.EXE in the Windows Start folder. This is a Trojan designed to open a backdoor access to compromised computer.

Deloder then copies a file called DVLDR32.EXE, a copy of the worm itself, onto infected machines.

Then from Symantec [securityresponse.symantec.com]:

W32.HLLW.Deloder is a network-aware worm that attempts to connect to a target host, using TCP port 445. This worm affects Windows 2000 and Windows XP only.

txbakers

4:19 pm on Mar 11, 2003 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



So, if port 445 is never open there's nothing to worry about?