• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

W32.Korgo Worm

Shelly21

Diamond Member
I was getting ready to leave, got sucked in by the management to stay and help with the possible out break of Korgo worm here.

Geez, like I could do anything with 800 plus desktops infected....
 
I don't know how that got passed the firewall, you'd think never since just last week, I had to wait four days for the "bastards" at DMZ to open a hole from XXXX to a print server that I built.

I'm running Shavlik's scanner on 4 servers that they told me were infected. I'm kinda baffled since they are new patched 2K servers that we just put into production. And they're running Trend!
 
Update, 800+ "desktops" are now infected. I'm still at work, the management wants us to "manually" patch and fix each desktops remotely. geeze, with 6 people at 5 minutes+ per desktop. I'll be here forever. 🙁

I'm trying to get Norton System Center to push it out, hopefully I won't be here until mid night or later.
 
Reboot the workstation/server over and over again.

You don't even have time to patch it. You have to run a "stop reboot" and then patch it.
 
How on Earth are you guys even infected? Korgo uses the same exploit as Sasser, so that should have been patched months ago.
 
I have no clue. All of the servers that we are responsible for are fine. Because *I* was the one who patched them all months ago.

All the infected machines are desktops. Now, I don't understand why I'm still at work when this is obviously a desktop issue. But I'll make them pay. starting with my dinner.
 
haha! thats what you get for not updating you machines...


whats the date of the patch btw? I dont think ive done any critical updates at work since the sasser
 
They are "wrapping" ports now to prevent further infection.

I'm working with the site in Utah with 50+ desktops while eating "Lobster Cantonese". I fear I'll be here until tomorrow. I've been here since 8am and I'm tire and stinky.
 
Originally posted by: halik
haha! thats what you get for not updating you machines...


whats the date of the patch btw? I dont think ive done any critical updates at work since the sasser

Well, like I said, I updated all my servers, I'm just here to clean up for the desktop support.

The patch in question is 4-011
 
I do for my servers.

I think the desktop team uses SMS for desktop updates.

I'm still here, and I'm still on batch one of 26 desktops. 5-6 people just got sucked in by the management to work from home.
 
Originally posted by: Shelly21
I do for my servers.

I think the desktop team uses SMS for desktop updates.

I'm still here, and I'm still on batch one of 26 desktops. 5-6 people just got sucked in by the management to work from home.

heh you run windows on your servers? 🙂 I guess you like the challenge and checking cert.org every 6 hours ....
 
Er, we still have servers that were upgraded from windows 3.51 to NT4.0 running on Compaq 1500. (p150?)

However, it seems like this worm is only affecting desktops running XP.

I'm very tire right now, keeping my eyelids open with toothpicks. Maybe I'll order sushi for dinner tonight. I'm munching on D'aim candies right now and taking a break.
 
Sumbitch! The Korgo worm infected my laptop yesterday and I have the $#%^ing patch!!! Now I have to make sure my home network is not infected when I get home much much later. 🙁

The worm is using random ports to infect others so unless you have no ports open on your firewall, you're not safe.
 
Originally posted by: Shelly21
Sumbitch! The Korgo worm infected my laptop yesterday and I have the $#%^ing patch!!! Now I have to make sure my home network is not infected when I get home much much later. 🙁

The worm is using random ports to infect others so unless you have no ports open on your firewall, you're not safe.

Howd it get to your laptop? How do you know it was infected?
 
Originally posted by: Gobadgrs
Originally posted by: Shelly21
Sumbitch! The Korgo worm infected my laptop yesterday and I have the $#%^ing patch!!! Now I have to make sure my home network is not infected when I get home much much later. 🙁

The worm is using random ports to infect others so unless you have no ports open on your firewall, you're not safe.

Howd it get to your laptop? How do you know it was infected?

From SARC:

W32.Korgo.E is a minor variant of W32.Korgo.D. This worm propagates by exploiting the LSASS vulnerability on TCP port 445 (as described in Microsoft Security Bulletin MS04-011). It also opens backdoors on TCP ports 113 and 3067

So maybe you have a port open, Shelly? You shouldn't have gotten infected if you're patched and you have all your ports closed.
 
Back
Top