Worm.Mocbot.a
Aug 18, 2006 - Rising
 

Rising Antivirus Virus Alert:  Worm.Mocbot.a and Variants

 

 

Description

Worm.Mocbot.a is also known as:

It makes use of the following Exploit:
– MS06-040

Worm.Mocbot.a and its variants take advantage of MS06-040 vulnerability to propagate via network. It will crush system services and block access to internet.

Worm.Mocbot will automatically search vulnerable machines through network. When it exploits, it will download and execute malicious files on victim machines. It connects to an IRC Server/Channel and receives remote commands from hackers or malicious users. Hackers and steal user’s bank account, password and other privacy information.

 

Type: Worm

Risk: Dangerous

Systems Affected: Windows 95, 98, NT, 2000,  XP,  Windows Server 2003

Date discovered: 14 Aug 2006

In-The-Wild: YES

Method of Propagation: Local Network

Rising Antivirus version to detect/repair: 18.40.01

 

Recommendation

Update your Rising Antivirus to version 18.40.01 or above and perform a full scan of your computer. Enable Auto-Protect ability when connecting to internet.  Rising Antivirus  can protect your system against this malicious threat. Users should also download and install MS-06-040 patch.

 

Worm/IRCBot.9374 (AntiVir), Backdoor.IRCBot.ST (BitDefender), Win32.HLLW.Nert (Dr Web), Win32.IRCBot.jk (eSafe), Win32/Cuebot.K!Worm (eTrust-INO), Backdoor.IRCBot.st (Ewido), W32/Ircbot.TT (F-Prot), Backdoor.Win32.IRCBot.st (F-Secure), W32/Graweg.A!tr.bdr (Fortinet), Backdoor.Win32.IRCBot.st (Ikarus), Backdoor.Win32.IRCBot.st (Kaspersky), IRC-Mocbot!MS06-040 (McAfee), Backdoor:Win32/Graweg.B (Microsoft), Win32/IRCBot.OO trojan (Nod32), W32/Oscarbot.KD.worm!CME-482 (Panda), Backdoor.IRCBot.st (QuickHeal), W32/Cuebot-M (Sophos), W32.Wargbot (Symantec), WORM_IRCBOT.JK (Trend Micro).