W32/Acebot-A

Category: Viruses and Spyware Protection available since:29 Jul 2002 00:00:00 (GMT)
Type: Win32 worm Last Updated:29 Jul 2002 00:00:00 (GMT)
Prevalence: No Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Acebot-A is a network worm which spreads over open network shares and has backdoor capabilities.

Upon execution the worm drops itself to the Windows system folder as a randomly named executable and deletes itself from the current location. W32/Acebot-A sets the following registry entry

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Dianostic

so that it is run on startup.

The worm attempts to join an IRC channel to listen for commands and is also able to circumvent the firewall products Sygate Personal Firewall, Tiny Personal Firewall, ZoneAlarm Pro and ZoneAlarm.

download Try Sophos products for free
Download now