W32.Celebite.Worm
Aliases: W32/Celebit.worm [McAfee], I-Worm.Celebit [KAV], W32/Celebit-A [Sophos]
Variants:
Classification: Malware
Category: Computer Worm
Status: active & spreading
Spreading: slow
Geographical info: Asia, North and South America, and some parts of Europe and Australia
Removal: easy
Platform: W32
Discovered: 03 Jun 2003
Damage: Low
Characteristics: This threat is classified as a Worm - Mass Mailer. A mass mailing e-mail worm is self-contained malicious code that propagates by sending itself via e-mail.
W32.Celebite.Worm Removal Tool
If you have Malware on your computer it will cause annoyances and will damage your system. You should either:
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
RECOMMENDED:
We recommend that you scan your system for malware. Our partner has a computer worm removal tool to automatically clean W32.Celebite.Worm from your computer.
More details about W32.Celebite.Worm
The program is identified as a network worm. The W32.Celebite.Worm application propagates itself through Internet Relay Chat (IRC) channels. The program exploits the vulnerabilities of the Windows operating system. The security gaps allow the application to execute on the connected computers with administrator privileges. The program utilizes network shares protected with weak passwords and unsecured folders to distribute threats to the computers within the network. The application is encrypted with a predefined list of user names and passwords to be used on secured network shares.The W32.Celebite.Worm program has backdoor functions. The application opens the Transmission Control Protocol (TCP) port to establish connection with an IRC server.A remote user may send commands to the computer by joining an IRC channel. The remote commands are sent via IRC channels. These remote instructions may include termination of running processes, modification of system configuration and download of additional files from the Internet. The W32.Celebite.Worm application uses rootkit functions to hide its operation on the computer. The program utilizes a rootkit tool to rename its core components to appear as legitimate Windows processes. The rootkit technology used by the application disables security utilities on the computer such as personal firewalls and anti-virus programs. The application may terminate processes related to the W32.Celebite.Worm program.
Browse for more malware information
- W32.Celebite.Worm
- W32.Ceted
- W32.Chaim
- W32.Check.Mirc
- W32.Chiko
- W32.Chir.B@mm
- W32.Chod.B@mm
- W32.Choke.Worm
- W32.Cianam.Worm
- W32.Ciosor
- W32.Cissi.A@mm
- W32.Clunk.A
- W32.Collo
- W32.Condown.A
- W32.Cone.B@mm
- W32.Conedi.Worm
- W32.Culler.A
- W32.Cycle
- W32.Dabber.A
- W32.Dafet.A
- W32.Dalbug.Worm
- W32.Danber
- W32.Darby.B
- W32.Darjen
- W32.Darker.Worm
- W32.Dasher.A
- W32.Datom.Worm
- W32.Dawin
- W32.Debanpass
- W32.Debsis.A