Home > Support > Global Security Advisor 

Virus Detail

Win32.Spybot

Date Published:
9 Jul 2003

Last Updated:
13 Jan 2005

Threat Assessment

Overall Risk:   Low
Wild:  Low
Destructiveness:  Medium
Pervasiveness:  Medium

Characteristics

Type : Worm

Category : Win32

Also known as:  W32.Donk.R, Win32/P2P.SpyBot.Variant.Worm, Win32.Spybot.gen, W32.Spybot.Worm (Symantec), W32/Spybot.worm.gen (McAFee)

Immediate Protection Info

 
SignatureProductRemoval Instructions
23.61.65
eTrust Antivirus v7/8* (InoculateIT Engine)
5.x/2512
eTrust EZ Antivirus 5.x
6.x/4734
eTrust EZ Antivirus 6.1x
23.61.65
eTrust InoculateIT 6.0
eTrust Antivirus 6.0
43.65
Inoculan/InoculateIT 4.x
10.5x/4734
Vet Anti-Virus 10.5x
 
 

Description

Win32.Spybot is an open soure irc bot. Due to the open and modular manner in which the source for this bot is distributed, there are many slightly different variants of this bot in the wild. Most will allow a victim's machine to be controlled in some manner by a remote user via IRC (Internet Relay Chat), while others may have the ability to spread via P2P networks. 

Apart from having standard backdoor functionality, such as the ability to:

  • Gather configuration information about the local machine, including connection type, cpu speed and general information regarding the local drives.
  • Install or delete files on the local machine.
  • Perform other miscellaneous commands on the local machine.

Win32.Spybot may also be able to (depending on the variant):

  • Spread via: KaZaA P2P networks, or by using backdoor programs, Kuang or Sub Seven
  • Download files via the Internet
  • Keylog (i.e. log keystrokes on the affected machine)
  • Kill firewall or antivirus software processes to avoid detection
  • Act as an HTTP server

Spybot installs itself via the registry by default by modifying the following keys:

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

These 'Bots' are a popular tool for conducting a Distributed Denial of Service against a target, although they can also be used for a number of other illegitimate purposes, such as port scanning, spamming or flooding unsuspecting targets. 

Analysis by Scott Molenkamp

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All

Security Resources

 
 
Page Tools