Jump to content

Recommended Posts

Posted

I wasn't infected nor seen any case of infection yet but everyone should be extra-careful as this new worm could spread using hole in rdp.

Here is the thread at MS Technet.

Description of this worm is there.

At this time most antivirus doesn't even detect it (so automatic removal isn't an option).


Posted

Yes it would be very wise to filter at list from source ips and block when not needed.

Although MS say it use a dictionary attack on weak passwords, it seems it was able to spread on other system as well.

It seems almost every years (or so) a real bad worm spread in august (the only exception is conficker).

Posted

I was reading about this on Sophos, but they seem to be saying there is more talk about this than actual reported infections. Although that may be related to most scanners' inability to detect it.

Posted

Yes that might be true but anyway, being aware of such suspicious behavior might help avoid hours of diagnostic.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...