1. Symantec/
  2. Security Response/
  3. W32.Kwbot.S.Worm@mm


Risk Level 2: Low

December 2, 2003
February 13, 2007 12:14:33 PM
Also Known As:
Backdoor.IRCBot.gen [KAV]
Systems Affected:

W32.Kwbot.S.Worm@mm is a mass-mailing variant of W32.Kwbot.Worm. The worm attempts to spread through the Kazaa file-sharing network and uses its own SMTP engine to email itself to contacts in the Windows address book.

The email message has the following characteristics:

(randomly chosen from the following list)
    • check this out
    • please give me feedback on this
    • long time no see
    • pictures of the kids
    • good antivirus
Attachment: app.exe

W32.Kwbot.S.Worm@mm is packed with UPX v1.20.

Antivirus Protection Dates

  • Initial Rapid Release version December 2, 2003
  • Latest Rapid Release version December 2, 2003
  • Initial Daily Certified version December 2, 2003
  • Latest Daily Certified version December 2, 2003
  • Initial Weekly Certified release date December 3, 2003
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Sergei Shevchenko

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube