TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_SIWEOL.B
Overview

Malware type: Worm

Aliases: No Alias Found

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Infection Channel 1 : Propagates via removable drives


Infection Channel 2 : Propagates via shared drives


Description: 

This worm may arrive from a small number of iPod products, a popular MP3 player manufactured by Apple. Although included in an iPod, it does not affect MAC computers or iPods.

It propagates via mapped drives. It lists all mapped drives on an affected system and drops several files in the root folder. It also propagates via removable drives such as flash disks and floppy disks.

It has backdoor capabilities. Using random ports, it connects to a remote user. Once a connection is established, the remote user issues commands on the affected system.

Moreover, this worm is capable of stealing IP addresses and open ports. It then sends the stolen information to certain URLs.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jun. 21, 2006 6:48:03 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.