Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Dec 1st, 2008, 8:15pm
   Mischel Internet Security Forum
   Malware
   Trojans
(Moderators: Helena, Gavin_Coe, Magnus)
   W32/Nachi.A
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: W32/Nachi.A  (Read 324 times)
Ian
Stole All the Forum Stars
********



Good things come to those who wait ...

   


Posts: 2913
W32/Nachi.A
« on: Aug 20th, 2003, 6:26pm »
Quote Quote  Modify Modify

A Blaster variant, perhaps the product of the Chinese 'DCOM RPC Exploit' toolkit that's out there for folk to play with. This one is 'nicer' than most because it has a 'sell-by' date...
 
W32/Nachi.A This malicious code is programmed to exploit the RPC DCOM vulnerability that affects some versions of the Windows operating system in order to spread to as many computers as possible.  
 
Nachi.A does not spread via e-mail but attacks remote machines via TCP/IP and tries to cause a buffer overflow in them. After doing this, the attacked computer is forced to download a copy of the worm, which is done through a TFTP (Trivial File Transfer Protocol) server incorporated in this worm.  
 
This worm, which originated in China, can also use another exploit known as WebDav. Information about this exploit and the patch to fix it are available at the following address:  
http://www.microsoft.com/technet/treeview/default.asp?url=/technet/secur ity/bulletin/ms03-007.asp  
 
The worm is programmed to delete itself from the affected computer in 2004. Another interesting characteristic of Nachi.A is that it can uninstall the Blaster worm. In order to do this, it destroys the process and deletes the files belonging to this worm. However, not only does it remove this worm but it also installs the Microsoft patch that fixes the vulnerability it exploits on affected computers.
IP Logged

... but crap arrives pretty much straight away.
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register