- June 21, 2004
- February 13, 2007 12:24:30 PM
- Windows 2000, Windows XP
W32.Korgo.T is a variant of W32.Korgo.N
. This worm attempts to propagate by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011
) on TCP port 445. It also listens on TCP ports 113, 5111, and a random port between 256 and 8191.
- Definitions dated prior to June 28, 2004 detect this threat as W32.Korgo.N.
- Symantec Security Response has developed a removal tool to clean the infections of W32.Korgo.T.
Antivirus Protection Dates
Initial Rapid Release version June 22, 2004
Latest Rapid Release version September 28, 2010 revision 054
Initial Daily Certified version June 22, 2004
Latest Daily Certified version September 28, 2010 revision 036
Initial Weekly Certified release date June 23, 2004
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Kaoru Hayashi