Dilbert


Name: Dilbert
Aliases: I-Worm.Dilbert, W32/Dilbert.worm, Troj_Dilber,
Ports:
Files: Dilbertdance.jpg.exe - Setup_.exe - Sendmail.vbs - - 54,272 bytes
Created: 2000
Requires:
Actions: Worm / Mail trojan / Virus dropper / Network trojan
Alters Win.ini. The worm also spreads to shared disks in a local network. Every month the worm drops five viruses on different days: Bolzano, CIH_15, Links, Winsk and Bee_Aoc. The worm is packed using ASPack, which makes a little bit trickier to fin by Antivirus software.
Versions:
Registers: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices\ HKEY_USERS\DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\
Notes: Works on Windows, together with MS Outlook.
Country:
Program: Written in Delphi.

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>