Discovered: August 8, 2003
Updated: February 13, 2007 12:19:41 PM
Also Known As: Backdoor.Sdbot.gen [Kaspersky], W32/Sdbot.worm.gen [McAfee]
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
W32.HLLW.Moega is a worm with backdoor capabilities that attempts to spread through the local area network. The worm attempts to open ports 139 and 445, as well as steal sensitive information.
The executable for W32.HLLW.Moega may look similar to the icon for Windows XP's Windows Update executable, Wupdmgr.exe. See step 1 of the "Technical Details" section for an illustration.
Several minor variants of this worm have been found. Some of them may be packed with UPX or PeCompact.
Protection
-
Initial Rapid Release version August 8, 2003
-
Latest Rapid Release version August 20, 2008 revision 017
-
Initial Daily Certified version August 8, 2003
-
Latest Daily Certified version January 20, 2009 revision 048
-
Initial Weekly Certified release date August 11, 2003
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
-
Wild Level: Low
-
Number of Infections: 0 - 49
-
Number of Sites: 0 - 2
-
Geographical Distribution: Low
-
Threat Containment: Easy
-
Removal: Moderate
Damage
Distribution
-
Distribution Level: Medium
Writeup By: Kaoru Hayashi