We're gradually updating threat actor names in our reports to align with the new weather-themed taxonomy. Learn about Microsoft threat actor names
Worm:Win32/Wootbot.EI
Aliases: Win32/Wootbot.worm.143360 (AhnLab) Backdoor.Wootbot!bL/87MSqLxE (VirusBuster) Win32/Dorkbot.C worm (ESET) Backdoor.Win32.Wootbot (Ikarus) Backdoor.Win32.Wootbot.gq (Kaspersky) WORM_WOOTBOT.LOL (Trend Micro)
Summary
Worm:Win32/Wootbot.EI is a worm that includes a backdoor component, which connects to an IRC server and awaits commands from remote attackers. For example, an attacker can send a command to distribute the worm to other computers by exploiting a vulnerability in the Windows service LSASS, described in Microsoft Security Bulletin MS04-011.
To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat:
- Microsoft Security Essentials
- Microsoft Safety Scanner
- Microsoft Windows Malicious Software Removal Tool
For more information on antivirus software, see http://www.microsoft.com/windows/antivirus-partners/.