Skip to main content
Skip to main content
Published Sep 07, 2011 | Updated Sep 15, 2017

Worm:Win32/Wootbot.EI

Detected by Microsoft Defender Antivirus

Aliases: Win32/Wootbot.worm.143360 (AhnLab) Backdoor.Wootbot!bL/87MSqLxE (VirusBuster) Win32/Dorkbot.C worm (ESET) Backdoor.Win32.Wootbot (Ikarus) Backdoor.Win32.Wootbot.gq (Kaspersky) WORM_WOOTBOT.LOL (Trend Micro)

Summary

Worm:Win32/Wootbot.EI is a worm that includes a backdoor component, which connects to an IRC server and awaits commands from remote attackers. For example, an attacker can send a command to distribute the worm to other computers by exploiting a vulnerability in the Windows service LSASS, described in Microsoft Security Bulletin MS04-011.

To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:

For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.

Follow us