RE: W32.GAOBOT.AFJ Virus in Win32.exe file

From: Subramanian S [MSFT] (v-subs_at_online.microsoft.com)
Date: 05/10/04


Date: Mon, 10 May 2004 03:29:49 GMT

Hi,

W32.Gaobot.AFJ is a worm that spreads through open network shares,
backdoors that the Beagle and Mydoom worms install, and several Windows
vulnerabilities, including:
--DCOM RPC Vulnerability (described in Microsoft Security Bulletin
MS03-026) using TCP port 135.
--Workstation Service Buffer Overrun Vulnerability (described in Microsoft
Security Bulletin MS03-049) using TCP port 445. Windows XP users are
protected against this vulnerability if Microsoft Security Bulletin
MS03-043 has been applied. Windows 2000 users must apply MS03-049.
--Exploits the Microsoft Windows Local Security Authority Service Remote
Buffer Overflow (described in Microsoft Security Bulletin MS04-011).

http://securityresponse.symantec.com/avcenter/venc/data/w32.gaobot.afj.html
gives you information on removal of W32.Gaobot.AFJ.

pls follow the same & ensure the virus is cleaned and try again.

Regards,
Subbu

---
Subramanian .S
v-subs@online.microsoft.com
Microsoft GPS
This posting is provided "AS IS" with no warranties, and confers no rights. 


Relevant Pages

  • Re: Pathes Not Applying
    ... they are placed in the Windows folder and are named KBxxxxxx.log ... Microsoft Security Bulletin MS04-035 ... Vulnerability in Windows Shell Could Allow Remote Code Execution ... torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway ...
    (microsoft.public.security)
  • Re: Its Tuesday and its Patch Day
    ... It depends on your OS - on Windows XP Pro, Windows Update told me I needed 6 ... >> Microsoft Security Bulletin MS04-024 ... >> Vulnerability in Windows Shell Could Allow Remote Code Execution ...
    (microsoft.public.frontpage.client)
  • Re: No Windows XP SP2 Updates here recently
    ... -- Critical Update for Windows XP ... -- Security Update for Windows XP ... - Vulnerability in Windows Could Allow Information Disclosure ... -- Microsoft Security Bulletin MS04-041 ...
    (microsoft.public.windowsupdate)
  • SecurityFocus Microsoft Newsletter #163
    ... MICROSOFT VULNERABILITY SUMMARY ... Bugzilla Javascript Buglists Remote Information Disclosure V... ... Microsoft Internet Explorer DHTML Drag and Drop Local File S... ... Microsoft Windows Workstation Service Remote Buffer Overflow... ...
    (Focus-Microsoft)
  • SecurityFocus Microsoft Newsletter #176
    ... MICROSOFT VULNERABILITY SUMMARY ... Microsoft Windows XP HCP URI Handler Arbitrary Command Execu... ... PHPNuke Category Parameter SQL Injection Vulnerability ... Microsoft Baseline Security Analyzer Vulnerability Identific... ...
    (Focus-Microsoft)