Discovered: April 16, 2003
Updated: November 30, 2007 10:19:46 AM
Also Known As: Win32.Spybot.gen [Computer Associates], Worm.P2P.SpyBot.gen [Kaspersky], W32/Spybot-Fam [Sophos], W32/Spybot.worm.gen [McAfee], WORM_SPYBOT.GEN [Trend]
Type: Worm
Infection Length: Varies.
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
CVE References: CVE-2001-0876,
CVE-2002-1145,
CVE-2003-0109,
CVE-2003-0812,
CVE-2004-0120,
CVE-2006-2630,
CVE-2006-3439,
CVE-2003-0352,
CVE-2003-0533,
CVE-2003-0717,
CVE-2005-1983
W32.Spybot.Worm is a detection for a family of worms that spreads using the Kazaa file-sharing network and mIRC. This worm can also spread to computers that are compromised by common back door Trojan horses and on network shares protected by weak passwords.
W32.Spybot.Worm can perform various actions by connecting to a configurable IRC server and joining a specific channel to listen for instructions. Newer variants may also spread by exploiting the following vulnerabilities:
Protection
-
Initial Rapid Release version April 16, 2003
-
Latest Rapid Release version July 5, 2008 revision 005
-
Initial Daily Certified version April 16, 2003
-
Latest Daily Certified version July 5, 2008 revision 018
-
Initial Weekly Certified release date April 16, 2003
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
-
Wild Level: Low
-
Number of Infections: 0 - 49
-
Number of Sites: 0 - 2
-
Geographical Distribution: Medium
-
Threat Containment: Easy
-
Removal: Moderate
Damage
-
Damage Level: Medium
-
Releases Confidential Info: Sends personal data to an IRC channel.
-
Compromises Security Settings: Allows unauthorized commands to be executed on a compromised computer.
Distribution
-
Distribution Level: High
-
Shared Drives: Spreads using the KaZaA file-sharing network, as well as through mIRC.
-
Target of Infection: Remotely exploitable vulnerabilities.
Writeup By: Douglas Knowles