Win.ini file transferred using HTTP POST
| http-win.ini-transfer (8576) |
Description:
An attempt has been made to remotely access the system's WIN.INI file using a Web form. This attack may be trying to reconfigure the system, such as configuring a Trojan Horse to run when the system is restarted.
Many Trojan Horse programs and worms modify or access the WIN.INI file. One of the best known examples is the ExploreZip worm.
Platforms Affected:
- Microsoft, Windows
- Microsoft, Windows 2000
- Microsoft, Windows 95
- Microsoft, Windows 98
- Microsoft, Windows NT 4.0
- Various vendors, HTTP
Remedy:
Verify that your antivirus and intrusion detection software is up-to-date. Should your system become infected with a worm, virus, or Trojan Horse program, refer to your antivirus vendor's documentation to determine how to disinfect and repair your system.
Consequences:
File Manipulation
References:
- IBM Internet Security Systems X-Force Database, ExploreZip worm destroys files on infected and connected systems at http://xforce.iss.net/xforce/xfdb/8238.
Reported:
Not available
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
