60,771 News Articles

Symantec warns of new worm variant

Antivirus users should update now to repel Rinbot

Security experts are urging users of Symantec's antivirus software to update it to combat a new variant of the worm known as either Rinbot or Delbot.

The worm exploits a vulnerability in Symantec software and seeks to set up botnets from which DOS (denial-of-service) attacks can be launched. It propagates by creating emails with the worm program attached or by attaching the program to outgoing email, said Ron O'Brien, a senior security analyst at Sophos.

Symantec has the worm listed as one of two latest threats today, and has issued a Daily LiveUpdate that protects against what the company calls W32.Rinbot.L. Sophos calls the worm W32/Delbot-L.

The worm takes advantage of weak passwords to install on machines including Microsoft SQL servers using Windows network APIs, such as the Messaging API, says O'Brien. The worm creates registry changes in systems it infects that must be removed. Symantec classifies removal as easy.

The worm was detected at work against servers in CNN's network Wednesday, according to O'Brien.

Send to a friend

Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story. Both your name and the recipient's name and address will not be used for any other purpose.