TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_WOOTBOT.GE
Overview

Malware type: Worm

Aliases: W32.Spybot.Worm, W32/Sdbot.worm

In the wild: Yes

Language: English

Platform: Windows 95, 98, ME, NT, 2000, XP

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Description: 

This worm exploits the Windows LSASS vulnerability to propagate across networks. This vulnerability is a buffer overrun that allows remote code execution. Detailed information about this vulnerability is available from the following Microsoft page:

This worm terminates processes that are related to security applications. It has backdoor capabilities and may execute commands issued by a remote malicious user on the host machine.

For additional information about this threat, see:
Solution
Technical Details

Description created: Feb. 16, 2005 9:21:52 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.