The worm emails itself to these addresses using its own SMTP engine.
The backdoor component of the worm drops an IRC backdoor which allows the remote user to perform a DoS (Denial of Service) attack and other illegal operations.
The worm also exploits the RPC DCOM Buffer Overflow (MS03-026) to remotely execute programs in vulnerable systems
The worm also tries to terminate antivirus and security related software.
This worm first appeared on 06th December, 2004.
Other
names of W32/Maslan Worm:
This Worm is also known as WORM_MASLAN.A, W32/Maslan-C.
Proland
Software is the developer of Protector Plus range of antivirus software
packages. Protector Plus 2007 is available for Windows Vista, Windows 95/98/Me, Windows
XP, Windows NT/2000/2003 servers and workstations, MS-Exchange 2000/2003, MS-DOS
and NetWare servers.
Protector Plus range of antivirus products
offer on-line virus detection and removal. All the packages have the ability
to detect and isolate all types of viruses, trojans, worms and other types
of malware.
Protector Plus antivirus software can detect and remove W32/Maslan Worm reliably.
These products are updated on a continuous basis and the latest upgrades
for all the platforms are made available for downloading from this site.