W32.HLLW.Moega

Risk Level 1: Very Low

Printer Friendly Page

Discovered: August 8, 2003
Updated: February 13, 2007 12:19:41 PM
Also Known As: Backdoor.Sdbot.gen [Kaspersky], W32/Sdbot.worm.gen [McAfee]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP


W32.HLLW.Moega is a worm with backdoor capabilities that attempts to spread through the local area network. The worm attempts to open ports 139 and 445, as well as steal sensitive information.

The executable for W32.HLLW.Moega may look similar to the icon for Windows XP's Windows Update executable, Wupdmgr.exe. See step 1 of the "Technical Details" section for an illustration.

Several minor variants of this worm have been found. Some of them may be packed with UPX or PeCompact.

Protection

  • Initial Rapid Release version August 8, 2003
  • Latest Rapid Release version August 20, 2008 revision 017
  • Initial Daily Certified version August 8, 2003
  • Latest Daily Certified version January 20, 2009 revision 048
  • Initial Weekly Certified release date August 11, 2003

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Moderate

Damage

  • Damage Level: Low

Distribution

  • Distribution Level: Medium

Writeup By: Kaoru Hayashi
Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security