- June 24, 2004
- February 13, 2007 12:24:36 PM
Also Known As:
- W32/Korgo.worm.v [McAfee], Worm.Win32.Padobot.m [Kaspersk, WORM_KORGO.V [Trend], Win32.Korgo.V [Computer Associ, W32/Korgo-T [Sophos]
- Windows 2000, Windows XP
W32.Korgo.V is a variant of W32.Korgo.N
. This worm attempts to propagate by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011
) on TCP port 445. It also listens on random TCP ports between 256 and 8191.
Definitions dated prior to June 28, 2004 detect this threat as W32.Korgo.Q.
Antivirus Protection Dates
Initial Rapid Release version June 24, 2004
Latest Rapid Release version May 25, 2013 revision 004
Initial Daily Certified version June 24, 2004
Latest Daily Certified version May 25, 2013 revision 006
Initial Weekly Certified release date June 25, 2004
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Kaoru Hayashi