Discovered: February 4, 2004
Updated: February 13, 2007 12:17:02 PM
Type: Worm
Systems Affected: Windows 2000, Windows NT, Windows Server 2003, Windows XP
W32.HLLW.Gaobot.JB is a minor variant of
W32.HLLW.Gaobot.BF that uses a different file name and is repacked with PECompact. It attempts to spread to network shares that have weak passwords and allows attackers to access an infected computer through an IRC channel.
The worm uses multiple vulnerabilities to spread, including:
When W32.HLLW.Gaobot.JB attempts to run on Windows 95/98/Me, it causes the error:
Error Starting Program
The PSAPI.DLL file is linked to missing export NTDLL.DLL:NtCreateProfile
Protection
-
Initial Rapid Release version February 5, 2004
-
Latest Rapid Release version February 5, 2004
-
Initial Daily Certified version February 5, 2004
-
Latest Daily Certified version January 15, 2008 revision 016
-
Initial Weekly Certified release date February 11, 2004
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
-
Wild Level: Low
-
Number of Infections: 0 - 49
-
Number of Sites: 0 - 2
-
Geographical Distribution: Low
-
Threat Containment: Easy
-
Removal: Easy
Damage
Distribution
-
Distribution Level: Medium
Writeup By: Paul Mangan