Virus Busters Home


The W32/Witty.worm Virus Attacks BlackIce Firewall Users

by Bruce P. Burrell (bpb@umich.edu)
for the U-M Virus Busters (virus.busters@umich.edu)
Last significant update: 20 March, 2004

This information can be freely reproduced in any medium, as long as the information is unmodified.

The W32/Witty virus is a network worm that affects only PC computers running Windows -- and only those Windows users who also are using version 3.6.ccf (and prior 3.6 versions) of the BlackIce firewall software. Users of other versions of BlackIce (including the most recent version, 3.6.ccg, and version 3.5 and prior), Macintosh users, and users of other non-Windows operating systems cannot be afflicted by this worm.

Witty does not spread via email. While its "target audience" is relatively small, UMnet reports that Witty caused noticeable network disruption on campus. Because of that and the fact that Witty contains a destructive payload, we are releasing this alert.

Here are some relevant facts about W32/Witty:

What should you do if:

For technical info on W32/Witty.worm, see e.g. Network Associates write-up on W32/Witty.worm (leaving our site) or F–Secure's write up (leaving our site).

The URL for this document is http://www.umich.edu/~virus-busters/witty.html

For virus or hoax info, please see our main page (http://www.umich.edu/~virus-busters/) or go to another reputable site, like The Urban Legends Reference Pages (leaving our site).

   -BPB

Virus Busters Home


Last updated: Monday, 22-Mar-2004 13:09:53 EST.
University of Michigan Virus Busters - virus.busters@umich.edu

visits to this page since 20 March, 2004 01:34 EDT