TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_WOOTBOT.HY
Overview

Malware type: Worm

Aliases: W32.Spybot.Worm, Worm:Win32/Wootbot

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Description: 

Like its earlier variants, this memory-resident worm spreads via network shares and has information theft capabilities.

It attempts to drop copies of itself to accessible network shares and then disables the shares it has accessed to prevent others from accessing them.

It steals the CD keys of popular games installed on the affected system, email addresses stored in different messaging applications, and other pertinent information about the affected system.

It has backdoor capabilities, which allows a remote malicious user to compromise the system through Internet Relay Chat (IRC).

For additional information about this threat, see:
Solution
Technical Details

Description created: Apr. 18, 2005 4:36:51 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.