Alias:Worm.Newbiero.54, W32.HLLW.Acebot,W32/AceBot.worm
Size:variable, ~163,840 byt 
Damage:Worm/AceBot allows hackers to attack the infected system and makes entries. 
VDF Version: 

DistributionThe worm can spread over local networks through shared directories.

Technical DetailsWorm/AceBot is a typical Backdoor Trojan, allowing hackers to access infected PCs unnoticed. There are more known versions of Worm/AceBot. The size is ~163,840 bytes. When activated, the worm copies itself in \Windows\System with a random name, for example: C:\Windows\System\Elrdvrp.exe.
Then, the original Trojan is deleted.
A value is given for the created file, which can look like this:
Microsoft Diagnostic C:\Windows\System\Elrdvrp.exe
in the registry:

Then the Trojan tries to connect an IRC server and to monitor on a port. This gives the hacker remote control. In this way, the hacker can do the following:
-start an ICMP/IGMP pack attack
-full control over system file
-upload from and download on the host computer
-start certain files
-computer log off
-terminate Trojan process
-PC shut-down.

The Trojan can terminate the following active firewalls"
Sygate Personal Firewall
Tiny Personal Firewall
ZoneAlarm Pro

It also tries to copy itself in the following shared network drive: C:\%WinDIR%\StartMenu\Programs\StartUp\Mscf.exe

Note: given the number of version, there can be differences in the file names used by the virus.
Die Beschreibung wurde erstellt von Crony Walker am Dienstag, 15. Juni 2004

