Symantec.com > Security Response > W32.Spybot.Worm

W32.Spybot.Worm

Risk Level 2: Low

Printer Friendly Page

Discovered: April 16, 2003
Updated: November 30, 2007 10:19:46 AM
Also Known As: Win32.Spybot.gen [Computer Associates], Worm.P2P.SpyBot.gen [Kaspersky], W32/Spybot-Fam [Sophos], W32/Spybot.worm.gen [McAfee], WORM_SPYBOT.GEN [Trend]
Type: Worm
Infection Length: Varies.
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
CVE References: CVE-2001-0876, CVE-2002-1145, CVE-2003-0109, CVE-2003-0812, CVE-2004-0120, CVE-2006-2630, CVE-2006-3439, CVE-2003-0352, CVE-2003-0533, CVE-2003-0717, CVE-2005-1983

W32.Spybot.Worm is a detection for a family of worms that spreads using the Kazaa file-sharing network and mIRC. This worm can also spread to computers that are compromised by common back door Trojan horses and on network shares protected by weak passwords.

W32.Spybot.Worm can perform various actions by connecting to a configurable IRC server and joining a specific channel to listen for instructions. Newer variants may also spread by exploiting the following vulnerabilities:



Protection

  • Initial Rapid Release version April 16, 2003
  • Latest Rapid Release version July 19, 2008 revision 019
  • Initial Daily Certified version April 16, 2003
  • Latest Daily Certified version July 19, 2008 revision 018
  • Initial Weekly Certified release date April 16, 2003

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Medium
  • Threat Containment: Easy
  • Removal: Moderate

Damage

  • Damage Level: Medium
  • Releases Confidential Info: Sends personal data to an IRC channel.
  • Compromises Security Settings: Allows unauthorized commands to be executed on a compromised computer.

Distribution

  • Distribution Level: High
  • Shared Drives: Spreads using the KaZaA file-sharing network, as well as through mIRC.
  • Target of Infection: Remotely exploitable vulnerabilities.

Writeup By: Douglas Knowles
PRINT THIS PAGE
Search by name
Example: W32.Beagle.AG@mm
Norton Green PC Service
Windows Vista Security