HEADS UP *Exploit-DcomRpc* Trojan
Trojan Name Risk Assessment
Exploit-DcomRpc Corporate User : Low
Home User : Low
Trojan Information
Discovery Date: 07/29/2003
Origin: Unknown
Length: Varies
Type: Trojan
SubType: Exploit
Minimum DAT:
Release Date: 4281
07/30/2003
Minimum Engine: 4.1.60
Description Added: 07/29/2003
Description Modified: 07/29/2003 4:09 PM (PT)
Trojan Characteristics:
This detection covers an exploit tool that makes use of the RPC Interface Buffer Overflow (7.17.03) vulnerability.
This exploit tool, creates a remote shell to provide access to a compromised system.
This tool is run on a Windows NT based system, to attack a Win2K/XP system.
Top of Page
Symptoms
N/A This is an attack tool, to exploit vulnerable remote systems.
Top of Page
Method Of Infection
N/A
Top of Page
Removal Instructions
All Users:
Use current engine and DAT files for detection. Delete any file which contains this detection.
Additional Windows ME/XP removal considerations
*FROM http://vil.nai.com/vil/content/v_100516.htm*