Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

W32.Kwbot.S.Worm@mm

Dec 2, 2003 3:19PM PST

Discovered on: December 02, 2003
Last Updated on: December 03, 2003 10:38:16 AM

W32.Kwbot.S.Worm@mm is a mass-mailing variant of W32.Kwbot.Worm. The worm attempts to spread through the Kazaa file-sharing network and uses its own SMTP engine to email itself to contacts in the Windows address book.

The email message has the following characteristics:

Subject: (randomly chosen from the following list)

check this out
please give me feedback on this
long time no see
pictures of the kids
good antivirus

Attachment: app.exe

W32.Kwbot.S.Worm@mm is packed with UPX v1.20.

Also Known As: Backdoor.IRCBot.gen [KAV]

Type: Worm

http://www.symantec.com/avcenter/venc/data/w32.kwbot.s.worm@mm.html

Discussion is locked