- Discovered:
- April 12, 2005
- Updated:
- February 13, 2007 1:03:54 PM
- Also Known As:
- Backdoor.Win32.IRCBot.ao [Kasp, W32/Sdbot.worm.gen.i [McAfee], WORM_SDBOT.BKW [Trend Micro]
- Type:
- Worm
- Systems Affected:
- Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
W32.Spybot.NLX is a worm that has distributed denial of service and back door capabilities.
The worm spreads through network shares protected by weak passwords and by exploiting the following vulnerabilities:
- The Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026).
- The Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011).
- The Microsoft Windows SSL Library Denial of Service Vulnerability (described in Microsoft Security Bulletin MS04-011).
- The Vulnerabilities in the Microsoft SQL Server 2000 or MSDE 2000 audit (as described in Microsoft Security Bulletin MS02-061) using UDP port 1434.
- The UPnP NOTIFY Buffer Overflow vulnerability (as described in Microsoft Security Bulletin MS01-059).
- The Workstation Service Buffer Overrun vulnerability (as described in Microsoft Security Bulletin MS03-049) using TCP port 445. Windows XP users are protected against this vulnerability if Microsoft Security Bulletin MS03-043 has been applied. Windows 2000 users must apply MS03-049.
- The DameWare Mini Remote Control Server Pre-Authentication Buffer Overflow vulnerability (described in CAN-2003-0960.)
Antivirus Protection Dates
- Initial Rapid Release version April 12, 2005
- Latest Rapid Release version April 12, 2005
- Initial Daily Certified version April 12, 2005
- Latest Daily Certified version April 12, 2005
- Initial Weekly Certified release date April 13, 2005
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
- Wild Level: Low
- Number of Infections: 0 - 49
- Number of Sites: 0 - 2
- Geographical Distribution: Low
- Threat Containment: Easy
- Removal: Moderate
Damage
- Damage Level: Medium
Distribution
- Distribution Level: Medium
Writeup By: John Canavan







