Wednesday, April 13, 2005

SCardClnt.exe: W32/Codbot-Gen

Sophos virus analysis: W32/Codbot-Gen: "Sophos Anti-Virus products detect members of the W32/Codbot family of worms as W32/Codbot-Gen. Worms detected as W32/Codbot-Gen provide backdoor Trojan functionality to a remote attacker via IRC channels. Such worms may spread to remote network shares with weak passwords in response to a command from a remote attacker. Members of W32/Codbot family typically attempt to exploit vulnerabilities, such as the LSASS vulnerability (MS04-011). "