Threat Search: 

ThreatExpert's Statistics for W32.Spybot.Worm [Symantec]:

W32.Spybot.Worm [Symantec] is also known as:
Threat AliasNumber of Incidents
W32/Sdbot.worm [McAfee]500
Generic.dx [McAfee]427
Mal/Generic-A [Sophos]379
Win32/IRCBot.worm.variant [AhnLab]325
Backdoor.Win32.Rbot.gen [Kaspersky Lab]294
W32/Sdbot.worm.gen.g [McAfee]259
Trojan.Win32.Crypt [Ikarus]256
Trojan.Win32.Crypt.aqt [Kaspersky Lab]253
Backdoor:Win32/Rbot [Microsoft]242
W32/Sdbot.worm.gen.a [McAfee]217
Backdoor:Win32/Rbot.gen [Microsoft]191
Backdoor.IRCBot!sd6 [PC Tools]176
Worm:Win32/Pushbot.gen [Microsoft]165
Backdoor.Rbot [Ikarus]164
Win32/IRCBot.worm.Gen [AhnLab]157
Net-Worm.Spybot [PC Tools]156
WORM_SPYBOT.GEN [Trend Micro]146
Trojan.Crypt!sd6 [PC Tools]143
Worm.Akbot.Gen [PC Tools]134
W32/Sdbot.worm.gen.x [McAfee]124
Troj/Agent-JKY [Sophos]121
Virus.Win32.IRCBot.BSX [Ikarus]118
Win-Trojan/Xema.variant [AhnLab]113
Generic PWS.y [McAfee]112
W32/Rbot-GSL [Sophos]112
Virus.Win32.Rbot [Ikarus]107
WORM_RBOT.GEN [Trend Micro]106
WORM_RBOT.GEN-1 [Trend Micro]104
Worm.Rbot.MCG [PC Tools]89
Backdoor.Win32.Rbot.aea [Kaspersky Lab]84
Backdoor.SpyBoter [PC Tools]82
W32/Virut.gen [McAfee]81
Backdoor.Win32.IRCBot.gen [Kaspersky Lab]80
W32/Rbot-Fam, W32/Rbot-Gen [Sophos]77
Backdoor.Win32.Rbot.aeu [Kaspersky Lab]74
Generic BackDoor [McAfee]67
Worm.RBot.Gen.14 [PC Tools]67
Backdoor.Win32.SdBot.eba [Kaspersky Lab]65
W32/Sdbot.worm.gen.h [McAfee]65
Backdoor.Rbot!sd5 [PC Tools]64
Backdoor.Win32.EggDrop.v [Kaspersky Lab]64
VirTool:Win32/CeeInject.gen!J [Microsoft]61
W32/Gaobot.worm.gen.u [McAfee]61
WORM_SDBOT.GAV [Trend Micro]60
BKDR_RBOT.ASA [Trend Micro]59
Virus.Win32.Virut.n [Kaspersky Lab]59
Backdoor.Win32.IRCBot [Ikarus]58
Backdoor.Win32.Rbot.aus [Kaspersky Lab]56
Mal/Packer [Sophos]56
W32/Sdbot.worm.gen [McAfee]56
Trojan:Win32/Ircbrute [Microsoft]55
Worm.RBot.Gen.16 [PC Tools]55
WORM_GAOBOT.DF [Trend Micro]55
Packed/Themida [PC Tools]54
W32/Virut.gen.a [McAfee]54
Backdoor:Win32/Ursap!rts [Microsoft]52
Exploit-DcomRpc.gen [McAfee]52
Net-Worm.Win32.Kolab [Ikarus]52
Backdoor.IRCBot!sd5 [PC Tools]50
W32/Sdbot.worm.gen.ci [McAfee]49
Mal/Behav-285 [Sophos]46
New Malware.bl [McAfee]46
Backdoor.Win32.SdBot [Ikarus]44
Backdoor.Win32.Rbot.aftu [Kaspersky Lab]43
New Malware.b [McAfee]43
VirTool.Win32.CeeInject [Ikarus]42
Generic BackDoor.k [McAfee]41
Win32.Virut.Gen [PC Tools]41
AdWare.BHO [Ikarus]39
Backdoor.SdBot!sd5 [PC Tools]39
Backdoor:Win32/Poebot.gen [Microsoft]39
Backdoor.Rbot.Gen [PC Tools]38
W32/Spybot.worm.gen [McAfee]38
Worm.IRCBot.UXP [PC Tools]38
Generic Dropper!ccb [McAfee]36
Trojan-Downloader.Win32.Agent.dadb [Kaspersky Lab]36
TrojanDropper:Win32/Jadtre.B [Microsoft]36
W32/Jadtre-A [Sophos]36
Win-Trojan/Agent.205824.AI [AhnLab]36
W32/Rbot-Fam [Sophos]35
PE_VIRUT.AV [Trend Micro]34
Troj/Inject-JC [Sophos]34
W32/Sdbot.worm.gen.ca [McAfee]34
Backdoor.Rbot [PC Tools]33
Backdoor.Win32.Rbot [Ikarus]33
Generic Downloader.x [McAfee]33
Trojan-Dropper.Agent [Ikarus]32
Win32.Virut.Gen.4 [PC Tools]32
Worm.Kolab.xc [PC Tools]32
Worm.RBot.UPX [PC Tools]32
Backdoor.Win32.Ciadoor.gn [Kaspersky Lab]30
BackDoor-EEH [McAfee]30
Trojan.Win32.Buzus [Ikarus]30
Worm.RBot.Gen.10 [PC Tools]30
StartPage-KG [McAfee]29
TROJ_XPACK.TY [Trend Micro]29
Backdoor.Win32.SdBot.aad [Kaspersky Lab]28
BackDoor-CEP [McAfee]27
W32/Sdbot.worm.gen.ax [McAfee]27
BKDR_MYBOT.AH [Trend Micro]26

W32.Spybot.Worm [Symantec] has the following possible countries of origin:
OriginNumber of Incidents
China60
Russian Federation43
Sweden41
Germany35
Israel24
United Kingdom19
Spain17
Canada16
Brazil8
Republic of Korea8
France7
Saudi Arabia6
Portugal5
Switzerland5
Italy4
Netherlands4
Austria3
Egypt3
Turkey3
Kuwait2
Romania2
Taiwan2
Australia1
Finland1
Oman1
Poland1
Thailand1
Ukraine1

W32.Spybot.Worm [Symantec] is known to be created as:
%AppData%\310234.exe
%AppData%\bifrost\server.exe
%AppData%\cogad\cogad.exe
%AppData%\csrss.exe
%AppData%\gadcom\gadcom.exe
%AppData%\jusched.exe
%AppData%\microsoft\dtsc\17323.exe
%AppData%\microsoft\dtsc\18192.exe
%AppData%\microsoft\winlog.exe
%AppData%\pidle\pidle.exe
%AppData%\svchost.exe
%CommonDesktopDir%\idm.patch.exe
%CommonPrograms%\startup\adobe.com
%DesktopDir%\setup_ver1.1482.0.exe
%DesktopDir%\setup_ver1.1482.01.exe
%FontsDir%\svchost.exe
%FontsDir%\unwise_.exe
%MyDocuments%\sound_mp3.1488.0.exe
%Profiles%\hpserviceprint.exe
%Profiles%\localservice\svhost32.exe
%Profiles%\msconfig32.exe
%ProgramFiles%\adobe\acrord32.dll
%ProgramFiles%\bifrost\server.exe
%ProgramFiles%\common files\ahc.exe
%ProgramFiles%\common files\spoolvs.exe
%ProgramFiles%\common files\system\dbot.exe
%ProgramFiles%\common files\system\dllregserv32.exe
%ProgramFiles%\common files\system\dscom.exe
%ProgramFiles%\common files\system\install.exe
%ProgramFiles%\common files\system\msasp32.exe
%ProgramFiles%\common files\system\msiwa32.exe
%ProgramFiles%\common files\system\msnmsgr.exe
%ProgramFiles%\common files\system\msnmssgr.exe
%ProgramFiles%\common files\system\scvhost.exe
%ProgramFiles%\common files\system\security.exe
%ProgramFiles%\common files\system\serviceupd.exe
%ProgramFiles%\common files\system\taskmrg.exe
%ProgramFiles%\common files\system\vnc.exe
%ProgramFiles%\common files\system\winsec.exe
%ProgramFiles%\common files\system\winsecup.exe
%ProgramFiles%\common files\system\winservice32.exe
%ProgramFiles%\drpcclean\drpcdel.exe
%ProgramFiles%\drpcclean\drpcmain.exe
%ProgramFiles%\drpcclean\drpctrans.exe
%ProgramFiles%\internet download manager\idm.patch.exe
%ProgramFiles%\internet explorer\keygen.exe
%ProgramFiles%\internet explorer\svchost.exe
%ProgramFiles%\outlook express\keygen.exe
%ProgramFiles%\sisisi.exe
%ProgramFiles%\sombrio.exe
%ProgramFiles%\stub.exe
%ProgramFiles%\super internet tv\onlinetv.exe
%ProgramFiles%\windows nt\txlctafo.exe
%ProgramFiles%\windowstn\updater.exe
%ProgramFiles%\winzip\winzip.exe
%Programs%\startup\userinit.exe
%System%\1.exe
%System%\1025.exe
%System%\1028.exe
%System%\1031.exe
%System%\1033.exe
%System%\1037.exe
%System%\1041.exe
%System%\1042.exe
%System%\1054.exe
%System%\1nternet.exe
%System%\2052.exe
%System%\3076.exe
%System%\3com_dmi.exe
%System%\5.26.exe
%System%\abbdet.exe
%System%\abpexsgo.exe
%System%\abylmda.exe
%System%\ad-aware.exe
%System%\adnzpe.exe
%System%\advjjtsm.exe
%System%\aebyohz.exe
%System%\aflfzs.exe
%System%\afubgy.exe
%System%\ag1.exe
%System%\agl23.exe
%System%\agldoc32.com
%System%\ahikzqor.exe
%System%\aig.exe
%System%\aiocfld.com
%System%\aiyvqidp.exe
%System%\akgo.exe
%System%\alala.exe
%System%\alfdyyxz.exe
%System%\alg2k.exe
%System%\algg.exe
%System%\alggg.exe
%System%\algose32.exe
%System%\algs.exe
%System%\alovxjmx.exe
%System%\amc.exe
%System%\amship.exe
%System%\angyam.exe
%System%\aniwlz.exe
%System%\anlly.exe
Notes:
  • %AppData% is a variable that refers to the file system directory that serves as a common repository for application-specific data. A typical path is C:\Documents and Settings\[UserName]\Application Data.
  • %CommonDesktopDir% is a variable that refers to the file system directory that contains files and folders that appear on the desktop for all users. A typical path is C:\Documents and Settings\All Users\Desktop (Windows NT/2000/XP).
  • %CommonPrograms% is a variable that refers to the file system directory that contains the directories for the common program groups that appear on the Start menu for all users. A typical path is C:\Documents and Settings\All Users\Start Menu\Programs (Windows NT/2000/XP).
  • %DesktopDir% is a variable that refers to the file system directory used to physically store file objects on the desktop. A typical path is C:\Documents and Settings\[UserName]\Desktop.
  • %FontsDir% is a variable that refers to a virtual folder containing fonts. A typical path is C:\Windows\Fonts.
  • %MyDocuments% is a variable that refers to the file system directory used to physically store a user's common repository of documents. A typical path is C:\Documents and Settings\[UserName]\My Documents.
  • %Profiles% is a variable that refers to the file system directory containing user profile folders. A typical path is C:\Documents and Settings.
  • %ProgramFiles% is a variable that refers to the Program Files folder. A typical path is C:\Program Files.
  • %Programs% is a variable that refers to the file system directory that contains the user's program groups. A typical path is C:\Documents and Settings\[UserName]\Start Menu\Programs.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).