New Deloder worm targets weak passwords

New Deloder worm targets weak passwords

A new worm on the Internet targets computers running the Microsoft Windows operating system, using easy-to-guess passwords for the Administrator account, according to alerts posted by a number of antivirus companies.

The new worm, W32/Deloder-A (Deloder), was considered a low risk for infection, F-Secure said. It was believed to have originated in China.

The worm attempts to connect to other computers on a network through TCP (Transmission Control Protocol) port 445, randomly generating IP (Internet Protocol) addresses to locate vulnerable machines.

Port 445 is used to access shared files on Windows machines with the SMB (Server Message Block) protocol.

When a vulnerable Windows machine was located, the worm attempted to log on to the machine's Administrator account by trying 50 likely passwords such as "admin", "password", "12345" and "administrator," F-Secure said.

If the worm succeeds in breaking the Administrator account password, it places copies of a backdoor, (trojan) program known as "inst.exe" in several locations on the infected machine.

The worm also modifies the machine's registry to run another copy of itself, "DVLDR32.EXE", according to advisories from F-Secure, Sophos and Symantec.

Machines running Windows 95, 98, NT, 2000, ME and XP were vulnerable to attack by Deloder, Symantec said.

No infections from Deloder have been reported and most firewalls block access to port 445. Still, many home computers without firewalls may be vulnerable to the new worm.

As of yesterday, most antivirus companies posted updated virus definitions to detect the new Deloder worm, as well as utilities to remove the worm from infected machines.

Follow Us

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Brand Post

Channel Roadmap

The Channel Roadmap is a bespoke content hub housing strategic priorities from technology vendors for 2022 and beyond, partners can find the guidance on the key technologies and markets to pursue, to help build a blueprint for future success.

Show Comments