More detail... - http://asert.arbornetworks.com/2008/11/ms08-067-us ed-to-drop-ddos-bots/
November 3, 2008 - "...The exploit code is 67.exe , and the bot itself is 6767.exe . KernelBot is a Chinese origin DDoS bot... We first became aware of this bot during the CNN.Com attacks earlier this year... If you want to stop this one, you should block all web access to the domain ...