New Worm Targets Weak Windows Passwords
Deloder installs a backdoor program on PCs with easy-to-guess passwords.
Paul Roberts, IDG News Service
A new worm on the Internet targets computers running the Microsoft Windows operating system, using easy-to-guess passwords for the Administrator account, according to alerts posted by a number of antivirus companies.
The new worm, W32/Deloder-A (Deloder), appeared on Sunday and is considered a low risk for infection, according to an alert posted by F-Secure of Helsinki, Finland.
Deloder is believed to have originated in China, F-Secure said.
The worm attempts to connect to other computers on a network through TCP (Transmission Control Protocol) port 445, randomly generating IP addresses to locate vulnerable machines.
Port 445 is used to access shared files on Windows machines with the Server Message Block protocol.
Password Problems
When a vulnerable Windows machine is located, the worm attempts to log on to the machine's Administrator account by trying 50 likely passwords such as "admin," "password," "12345," and "administrator," F-Secure said.
If the worm succeeds in breaking the Administrator account password, it places copies of a backdoor, (trojan) program known as "inst.exe" in several locations on the infected machine.
The worm also modifies the machine's registry to run another copy of itself, "DVLDR32.EXE," according to advisories from F-Secure, Sophos, and Symantec.
Machines running Windows 95, 98, NT, 2000, ME and XP are vulnerable to attack by Deloder, Symantec said.
No infections from Deloder have been reported and most firewalls block access to port 445. Still, many home computers without firewalls may be vulnerable to the new worm.
As of Monday morning, most antivirus companies posted updated virus definitions to detect the new Deloder worm, as well as utilities to remove the worm from infected machines.
- Sponsored Resource:Improve your network with the right mix of features, performance and pricing.
- Sponsored Resource:Growing your business requires the right tools. Dell's networking servers can help.
- Sponsored Resource:Thinking about a new Laptop? Lenovo has models to meet everyone's needs.
- Sponsored Resource:Twitter: A how-to guide for using Twitter as a business tool.
- Sponsored Resource:Smartphone security threats are on the rise. Is it time to safegaurd your device?
Print 65% more pages than with refilled inks. Trust Original HP Inks. Hit Print Reliably.
Solve Tech Issues Fast
The Best of PC World
Featured APC Accessories For Your System
10% Off Entire Cart at Online Store
-
APC Back-UPS ES
Safeguards your equipment from damaging surges and spikes that travel along your utility & data lines.
- APC SurgeArrest Performance Highest level of protection for your professional computers, electronics and connected devices, as well as provides surge protection.
People who read this also read:
Best Prices on Antivirus Software
Norton AntiVirus 2009 (Full Product)Price: $14.89
Anti-Virus 2009 (Full Product)Price: $17.85
VirusScan Plus 2009 - 3-User (Full Product)Price: $12.99
VirusScan Plus 2009 (Full Product)Price: $9.99
McAfee VirusScan Plus 2008 (Full Product)Price: $3.23
BitDefender 1-Year Antivirus 2009 - 1 PC (MB11011001EN-M2)Price: $14.95
- 2007 Microsoft Office Suites Comparison This paper compares and contrasts four suites of the 2007 Microsoft Office system: Microsoft Office Standard 2007, Microsoft Office Professional Plus 2007, Microsoft Office Enterprise 2007 and Microsoft Office Ultimate 2007. This paper is intended to help organizations understand the applications and capabilities offered, and to identify the suite that best fits their needs.
- Windows Vista Migration: The Business Proposition It's not so much a matter of "if" but "when" for most organizations regarding migration to Windows Vista. Laying the groundwork now for this migration can yield higher ROI than waiting until later. This Computerworld Technology Briefing explains it all.


