I wasn't infected nor seen any case of infection yet but everyone should be extra-careful as this new worm could spread using hole in rdp.
Here is the thread at MS Technet.
Description of this worm is there.
At this time most antivirus doesn't even detect it (so automatic removal isn't an option).
Page 1 of 1
Be Carefull with a new worm spreading around Morto.A is a worm spreading through rdp
#2
Posted 30 August 2011 - 07:52 AM
Would it be wise to block RDP ports on systems that aren't configured to use it, at least until a common fix is available for this worm?
#3
Posted 30 August 2011 - 08:13 AM
Yes it would be very wise to filter at list from source ips and block when not needed.
Although MS say it use a dictionary attack on weak passwords, it seems it was able to spread on other system as well.
It seems almost every years (or so) a real bad worm spread in august (the only exception is conficker).
Although MS say it use a dictionary attack on weak passwords, it seems it was able to spread on other system as well.
It seems almost every years (or so) a real bad worm spread in august (the only exception is conficker).
#4
Posted 31 August 2011 - 08:22 AM
I was reading about this on Sophos, but they seem to be saying there is more talk about this than actual reported infections. Although that may be related to most scanners' inability to detect it.
#5
Posted 31 August 2011 - 12:23 PM
Yes that might be true but anyway, being aware of such suspicious behavior might help avoid hours of diagnostic.
#6
Posted 01 September 2011 - 05:40 PM
I have a friend who got this recently
This post has been edited by ricktendo64: 01 September 2011 - 05:43 PM
- ← Malwarebyes ?
- Malware Prevention and Security
- The system could not find the environment option that was entered →
Share this topic:
Page 1 of 1



Help

Back to top









