Schelfhout Aubertijn 2009-10-04 18:45:22 As Johannes Ullrich stated wisely in his comment, 445 is also used by the Win2k / WinXP worm "Lioten" also known as "iraq_oil.exe". Please ensure that your vulnerable operating system is patched and current.

W32.Randex.B is a network-aware worm that will copy itself to the following paths: \Admin$\system32\msslut32.exe \c$\winnt\system32\msslut32.exe on computers with weak administrator passwords When W32.Randex.B is executed, it does the following: Caclulates a This file has been identified as a program that is undesirable to have running on your computer.

W32/Sluter-A exploits weak network security. They're calling it Rbot.cc.

Road Rage 2004-06-27 02:36:36 This seems to be some new type of variant that looks similar to many. K-OTik.COM (TechNet) 2004-02-16 22:51:21 Port 445 also used to exploit the Windows ASN.1 vulnerability (MS04-007) see : http://www.k-otik.com/exploits/02.14.MS04-007-dos.c.php George Assai 2004-01-30 19:55:18 Port 445 is used for Windows File Sharing.

Under certain circumstances, this can also be an indication of a virus. Description Added by the SLUTER-A WORM!

Phil Brammer 2003-12-17 17:41:55 Please see http://www.nipc.gov/warnings/advisories/2003/Potential7302003.htm for the latest on an RPC exploit against Microsoft operating systems.

It operates in several modes (not at same time). Bad news for spam. W32/Sluter-A will then schedule a job to start the worm on the compromised computer.W32/Sluter-A creates the following registry entry so that the worm is run when Windows starts up:HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Superslut = msslut32.exeRecovery:

An example would be "svchost.exe" - which doesn't appear in either under normal conditions but does via CTRL+ALT+DEL. W32/Sluter-A will then schedule a job to start the worm on the compromised computer."In case anyone is interested, here's what it looked like to me:06/17/03 13:08:54 GMT: connection to 66.75.XXX.XXX:445 from One mode tries to get out to sites on web and the other tries to crack passwords on accounts (I think it starts by going through host file..)this results in account File Location Unknown This entry has been requested 1,585 times.

From now on I will refer to the "client" as the computer from where you map drives and other shared resources, and to the "server" as the computer with resources that Adam Thompson 2004-11-11 09:35:49 New variant seen at two customer sites as of Tuesday November 9th, called "morbot". Msslut32.exe error codes are often brought on in one way or another by faulty files in the Microsoft Windows OS. Functionality appears VERY similar to rBot / rxBot.