Worm W32.Linkbot. It uses LSASS Buffer Overrun Vulnerability. http://www.microsoft.com/technet/securit... Adds value "Windows DLL Loader" = "%system%\defragfatz.exe" to the Windows startup registry key. Opens an Ident Daemon listening on TCP port 113. Allows the remote control of the infected computer.