- Discovered:
- July 8, 2004
- Updated:
- February 13, 2007 12:08:19 PM
- Also Known As:
- W32.Poco
- Type:
- Worm
- Systems Affected:
- Windows 2000, Windows XP
W32.Korgo.Y is a worm that attempts to propagate by exploiting the Microsoft Windows PCT Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011) on TCP port 113. Previous Korgo variants used a different vulnerability, the LSASS Buffer Overrun Vulnerability.
Virus definitions dated prior to July 14, 2004 detect this threat as W32.Poco.
Antivirus Protection Dates
- Initial Rapid Release version July 9, 2004
- Latest Rapid Release version September 28, 2010 revision 054
- Initial Daily Certified version July 9, 2004
- Latest Daily Certified version September 28, 2010 revision 036
- Initial Weekly Certified release date July 13, 2004
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Heather Shannon



