TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_WOOTBOT.M
Overview

Malware type: Worm

In the wild: Yes

Destructive: No

Language: English

Platform: Windows NT, 2000, XP

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Description: 

This worm exploits the Windows LSASS vulnerability to propagate across the network. This vulnerability is a buffer overrun that allows remote code execution.

Detailed information about this vulnerability is available from the following Microsoft page:

It also steals the Windows product ID and the CD keys of certain game applications. This worm also has backdoor capabilities and may execute commands issued by a remote malicious user in the host machine.

This malware runs on Windows NT, 2000, and XP.

For additional information about this threat, see:
Solution
Technical Details

Description created: Sep. 17, 2004 2:00:30 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.