Sophos

W32/Delbot-AO

Aliases
  • WORM_RINBOT.AD
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Network shares
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2007 (4.18)
Protection available since 28 April 2007 04:14:51 (GMT)
Detected by All Sophos products

Action

More Information

W32/Delbot-AO is a worm for the Windows platform which also allows a remote intruder to gain access and control over the computer.

W32/Delbot-AO spreads:
 - to computers vulnerable to common exploits, including: Symantec (SYM06-010) and SRVSVC (MS06-040)
 - to MSSQL servers protected by weak passwords

When first run W32/Delbot-AO copies itself to <System>\zmon.exe.

The following registry entry is created to run zmon.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Z
<System>\zmon.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer