File name: winlive.exe
Program name: Local area connection
Description: W32/Rbot-FPH worm and IRC backdoor.W32/Rbot-FPH spreads to other network computers by:- exploiting common buffer overflow vulnerabilities, including: ASN.1 (MS04-007)- networks protected by weak passwordsW32/Rbot-FPH includes functionality to:- access the internet and communicate with a remote server via HTTP- act as a proxy redirecting internet traffic- terminate security and anti-virus related processes- perform DDoS attacks- log keypresses- set up an FTP server- harvest clipboard data- start a remote shell (RLOGIN)- port scanning- packet sniffing- download/execute arbitrary files
Information added by: adderek at 27 March 2009
Hint: If winlive.exe file is a virus or trojan, we recommend to use a antivirus software or registry cleaner.
Read more about winlive.exe
|