TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_SPYBOT.H
Overview

Malware type: Worm

Aliases: W32/Spybot.H.worm

In the wild: No

Destructive: No

Language: English

Platform: Windows 95, 98, ME, NT, 2000, XP

Encrypted: Yes

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

Medium

Description: 

This worm spreads via the Kazaa peer-to-peer file-sharing network. It also acts as a backdoor and connects to a certain IRC (Internet Relay Chat) server. Through IRC, it is able to receive commands from a remote malicious user to process on the compromised machine.

It is capable of executing the following actions:

  • Log keystrokes
  • Steal cached passwords
  • Perform denial of service (DoS) attacks against other hosts
  • List and terminate running applications
  • Download, modify and execute files
  • Create directories
  • Retrieve system information
  • Scan ports
  • Control the CD-Rom tray

It runs on Windows 95, 98, ME, NT, 2000 and XP.

For additional information about this threat, see:
Solution
Technical Details

Description created: Oct. 14, 2003 7:10:58 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.