|
|
Worm.Plexus.C Worm Information
| Name: |
Worm.Plexus.C |
| Category: |
Worm |
| Alias: |
- Alias: W95/SouthPark@MM |
| Advice: |
Remove |
| Risk: |
Severe Risk
Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine. |
| Signatures:
|
exus.C@mm, W32/Dumaru-AK, NvClipRsv
Threat type: Worm - A worm is program that propagates by attacking other computers and copying itself to them. Worms may replace files, but do not insert themselves into files (as viruses do).
Advice: Remove
Threat risk: Severe Risk
Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine.
Description: Worm.Plexus.C@mm is a mass mailing worm that can also be spread by P2P networks.
Worm.Plexus.C consists of a dropper and a number of dropped files. The dropper copies itself to the filename upu.exe in the Windows system folder. The dropper also drops the files setupex.exe to the same folder and svchost.exe to the Windows folder, running them both.
Worm.Plexus.C spreads through Kazaa shares, email and through several vulnerabilities. Worm.Plexus.C spreads using vulnerabilities MS04-011 (CAN-2003-0533) LSASS and MS03-026.
Worm.Plexus.C also modifies the HOSTS files in an attempt to prevent anti-virus
updates.
Worm.Plexus.C listens on port 1250 for incoming connections which may contain updated copies of the worm or other files to install on the infected computer |
| Type: |
Worm - A worm is program that propagates by attacking other computers and copying itself to them. Worms may replace files, but do not insert themselves into files (as viruses do). |
Top Worm Visited Pages:
Wukill.mstray - Alias: Win32/HLLW.Wukill - 283 visits
Rbot - Alias: Backdoor.Rbot.Gen - 272 visits
SDBot - Alias: Wootbot.gen, Wootbot, Donk, spybot, Agobot - 224 visits
Trojan.Downloader.winstall - 177 visits
Worm.Brit.e - Alias: VBS/Chick.e@M virus - 86 visits
Worm.P2P.SpyBot.gen - 54 visits
Gaobot - 43 visits
Worm.Trilissa.e - 41 visits
Win32/Darby.O - 40 visits
JS.Lame - Alias: HTML.Lame - 39 visits
Random Worm Pages:
Worm.Satan
Worm.LamerOne.vbs
IRC.Worm.Mabra.e - Alias: IRC/Mabra
Virus.Anxiety.2242 - Alias: Quit
Worm.Wabbin
SuperNovae 999 worm
Evola - Alias: VBA/Generic.src
Worm.Lee.r
Worm.Mytob.D
Worm.Southpark - Alias: W95/SouthPark@MM
|
|