Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Please read the instructions for removing worms.
Windows NT/2000/XP
In Windows NT/2000/XP you will also need to edit the following registry key. The removal of this key is optional in Windows 95/98/Me.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE key:
HKLM\Software\Microsoft\Windows\
CurrentVersion\Run\Microsoft Dianostic
and delete it if it exists.
Close the registry editor and reboot your computer.
More Information
W32/Acebot-A is a network worm which spreads over open network shares and has backdoor capabilities.
Upon execution the worm drops itself to the Windows system folder as a randomly named executable and deletes itself from the current location. W32/Acebot-A sets the following registry entry
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Dianostic
so that it is run on startup.
The worm attempts to join an IRC channel to listen for commands and is also able to circumvent the firewall products Sygate Personal Firewall, Tiny Personal Firewall, ZoneAlarm Pro and ZoneAlarm.
