1. /
  2. Security Response/
  3. W32.Ackantta.B@mm


Risk Level 2: Low

February 25, 2009
March 4, 2009 7:46:58 PM
Also Known As:
W32/Xirtem@MM!8b1f20b9 [McAfee]
Infection Length:
266, 240 bytes
Systems Affected:
Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP
W32.Ackantta.B@mm is a mass-mailing worm that gathers email addresses from the compromised computer and spreads by copying itself to removable drives and shared folders.

Note: As of February 25, 2009, Symantec began observing an increase in the number of Trojan.Vundo infections as a direct result of W32.Ackantta.B@mm.

For more information, please see the following resources:

Antivirus Protection Dates

  • Initial Rapid Release version February 25, 2009 revision 036
  • Latest Rapid Release version February 19, 2013 revision 016
  • Initial Daily Certified version February 25, 2009 revision 039
  • Latest Daily Certified version May 6, 2011 revision 021
  • Initial Weekly Certified release date March 4, 2009
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment


  • Wild Level: Medium
  • Number of Infections: 1000+
  • Number of Sites: 10+
  • Geographical Distribution: Medium
  • Threat Containment: Moderate
  • Removal: Moderate


  • Damage Level: Medium
  • Payload: Spreads through email, removable drives and shared folders.
  • Large Scale E-mailing: Spams email.
  • Compromises Security Settings: Disables various security-related programs .


  • Distribution Level: Medium
  • Subject of Email: Job offer from Coca Cola!; Thank you for your application; You have got a new E-Card from your friend!; You have received A Hallmark E-Card!
  • Name of Attachment: copy of your CV.zip, e-card.zip, job-application-form.zip, postcard.zip
  • Target of Infection: Removable drives and shared folders.
Writeup By: Jeong Mun

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report