Discovered: September 9, 2003
Updated: February 13, 2007 12:07:09 PM
Also Known As: W32.HLLW.Gaobot.AA, Backdoor.Agobot.3.f [Kaspersky, W32/Agobot.AA [Frisk]
Type: Worm
Systems Affected: Windows 2000, Windows NT, Windows XP
W32.HLLW.Gaobot.AE is a minor variant of W32.HLLW.Gaobot.AA that attempts to spread to network shares with weak passwords. The worm also allows for a hacker to access an infected computer through IRC.
The worm uses the following vulnerabilities:
W32.HLLW.Gaobot.AE is compressed with UPX.
Note: Virus definitions dated prior to September 11, 2003 may detect this threat as W32.HLLW.Gaobot.AA.
Protection
-
Initial Rapid Release version September 11, 2003
-
Latest Rapid Release version March 3, 2008 revision 035
-
Initial Daily Certified version September 11, 2003
-
Latest Daily Certified version March 3, 2008 revision 037
-
Initial Weekly Certified release date September 11, 2003
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
-
Wild Level: Low
-
Number of Infections: 0 - 49
-
Number of Sites: 0 - 2
-
Geographical Distribution: Low
-
Threat Containment: Easy
-
Removal: Moderate
Damage
Distribution
-
Distribution Level: Medium
Writeup By: Kaoru Hayashi