- Discovered:
- May 25, 2004
- Updated:
- February 13, 2007 12:23:40 PM
- Type:
- Worm
- Systems Affected:
- Windows 2000, Windows NT, Windows XP
W32.Gaobot.ALW is a worm that spreads through open network shares and several Windows vulnerabilities. The vulnerabilities are:
- The Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026).
- The Microsoft Windows Workstation Service Remote Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS03-049).
- The Microsoft Windows WebDAV Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS03-007).
- The Microsoft UPnP NOTIFY Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS01-059).
- The Microsoft SQL Server Web Task Stored Procedure Privilege Escalation Vulnerability (described in Microsoft Security Bulletin MS02-061).
- The Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011).
The worm can act as a backdoor and attack other computers. It also attempts to kill the processes of many antivirus and security programs.
Antivirus Protection Dates
- Initial Rapid Release version May 26, 2004
- Latest Rapid Release version May 26, 2004
- Initial Daily Certified version May 26, 2004
- Latest Daily Certified version May 26, 2004
- Initial Weekly Certified release date May 26, 2004
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
- Wild Level: Low
- Number of Infections: 0 - 49
- Number of Sites: 0 - 2
- Geographical Distribution: Low
- Threat Containment: Easy
- Removal: Easy
Damage
- Damage Level: Medium
Distribution
- Distribution Level: Medium
Writeup By: Asuka Yamamoto







