W32/Delbot-P

Category: Viruses and Spyware Protection available since:05 Mar 2007 00:00:00 (GMT)
Type: Win32 worm Last Updated:05 Mar 2007 00:00:00 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Delbot-P is a worm with IRC backdoor functionality for the Windows platform.

W32/Delbot-P spreads:

- to computers vulnerable to common exploits, including: Symantec (SYM06-010)
- to MSSQL servers protected by weak passwords

W32/Delbot-P runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels. W32/Delbot-P is a worm with IRC backdoor functionality for the Windows platform.

W32/Delbot-P spreads:

- to computers vulnerable to common exploits, including: Symantec (SYM06-010)
- to MSSQL servers protected by weak passwords

W32/Delbot-P runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

When first run W32/Delbot-P copies itself to <System>\rst.exe.

The following registry entry is created to run rst.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Random Interface Network
System\rst.exe

download Try Sophos products for free
Download now