| |
|
| |
W32.Dumaru Worm |
| |
|
| |
Description:
The W32. Dumaru worm is a mass-mailing worm with its own
SMTP engine. The worm gathers email addresses from the computer
and sends an infected email spoofing the From: field with
security@microsoft.com.
It drops Trojan_Narod.A into the infected computer which then
connects to IRC port 6667 allowing remote users to perform
a Denial of Service attack against other systems. |
| |
|
| |
Example:
From: "Microsoft" <security@microsoft.com>
Subject: Use this patch immediately !
Message:
Dear friend , use this Internet Explorer patch now!
There are dangerous virus in the Internet now!
More than 500.000 already infected!
Attachment: patch.exe |
| |
|
| |
Removal Tool: W32.Dumaru
Worm Removal Tool (Symantec) or .zip
version |
| |
|
| |
Virus Details: Virus
details |