List of computer worms


NameAliasTypeSubtypeIsolation dateOriginAuthorFunctions and notes
BadtransBadtrans.29020, Badtrans.B, Badtrans.A,
I-Worm.BadtransII, Badtrans.gen
Mass mailerTrojanNovember 24, 2001PolandUnknownInstalled a keylogger; distributed logged information to one of 22 emails.
BagleBeagle, Mitglieder, Lodeight, Trojan.DL.BagleMass mailerTrojanJanuary 18, 2004UnknownUnknownSpread by email; certain variants had no subject and no text. Allowed attacker to access computers that were infected.
BlasterLovesan, MSBLASTMass DoS attacksLogic bomb August 11, 2003Hopkins, MinnesotaJeffrey Lee ParsonWidespread DDoS attacks targeted toward Bill Gates; contained message "billy gates why do you make this
possible ? Stop making money and fix your software!!". Caused over US$300,000,000 in damages, mostly to American infrastructure.
BrontokW32.Rontokbro@mm, BackDoor.Generic.1138, Worm.Mytob.GHOctober 3, 2005IndonesiaSpread through an Indonesian e-mail headed with "stop the collapse in this country"; destroys firewalls.
BuluBebekW32/VBWorm.QXEOctober 10, 2008
Code RedDoS payload, Defacement payloadJuly 2001Exploited Microsoft Internet Information Services to deface web pages and DOS a few set IPs.
Code Red IIAugust 4, 2001Exploited Microsoft Internet Information Server security holes.
ConfickerDownup, Downadup, KidoNovember 21, 2008
Daprosy WormWorm.Win32.VB.arz, W32.Autorun.worm.h, W32/Autorun-AMS, Worm:Win32/Autorun.UDTrojanMass mailerJuly 15, 2009Replaces folders with.EXE's, key logger, slow mass mailer.
DabberW32/Dabber-C, W32/Dabber.AMay 14, 2004
DoomjuiceFebruary 11, 2004Attack computers that had previously been infected by the Mydoom worm.
ExploreZipI-Worm.ZippedFilesJune 6, 1999Spread through zipped documents in a spam e-mail.
Father ChristmasHI.COMDecember 1988
HybrisSnow White, Full Moon, Vecna.22528December 11, 2000BrazilVecnaSpread through an e-mail from "haha@sexyfun.net".
ILOVEYOULoveletter, LoveBugWormMay 4, 2000Manila, Philippines
Kak wormOctober 22, 1999On the first day of any month, if the time was after 5 pm, Kak displayed a popup message box that read: "Driver Memory Error - Kagou-Anti-Kro$oft says not today !" Dismissing it would reboot the computer and then display the message again.
KlezOctober 2001
KoobfaceDecember 2008Targeted MySpace and Facebook users with a heading of "Happy Holidays".
Leap-AOompa-LoompaTrojan wormFebruary 14, 2006Most known for being the first virus targeting Mac computers.
MorrisNovember 2, 1988Robert Tappan MorrisWidely considered to be the first computer worm. Although created for academic purposes, the negligence of the author unintentionally caused the worm to act as a denial of service attack. It spread by exploiting known vulnerabilities in UNIX-based systems, cracked weak passwords, and periodically altered its process ID to avoid detection by system operators.
MydoomW32.MyDoom@mm, Novarg, Mimail.R, ShimgapiJanuary 26, 2004Fastest-spreading e-mail worm known; used to attack SCO Group
MylifeW32.MyLife.C@mmMass mailerTrojan April 2, 2002Mass deletes files on infected computers. Certain variants show a caricature of U.S. President Bill Clinton.
NavidadEmmanuel, W32.WachitMass mailerTrojanDecember 1, 2000South AmericaUnknownEmail appears to be in reply to someone the target has messages prior. Messages created by the virus are written entirely in Spanish.
NetskyFebruary 18, 2004GermanySven Jaschan
NimdaSeptember 2001Originally suspected to be connected to Al Qaeda because of release date; uses multiple infection vectors.
Psyb0tNetwork BluepillJanuary 2009
SadmindMay 8, 2001
SasserBig OneApril 30, 2004Sven JaschanNetwork worm. At startup, it kills the process lsass.exe, a windows process which handles file permissions. Killing lsass causes the computer to reboot one minute later, which would cause sasser to run again. This would continue in an infinite loop until the computer is shut down manually.
SircamSpread through e-mail with text like "I send you this file in order to have your advice."
SoberCME-681, WORM_SOBER.AGOctober 24, 2003Germany, possibly from National Democratic Party of GermanyWas disguised as e-mail from United States government.
SobigAugust 2003
SQL SlammerDDOS.SQLP1434.A, the Sapphire Worm, SQL_HEL, W32/SQLSlammerCaused global Internet slowdown.
StuxnetWin32/StuxnetJune 2010First malware to attack SCADA systems.
SwenSeptember 18, 2003
Toxbot2005The NetherlandsOpened up a backdoor to allow command and control over the IRC network.
UperingAnnoyer.B, SanyJuly 22, 2003
Voyager VoyagerWormOctober 31, 2005Targets Operating System running Oracle Databases.
W32.Alcra.FWin32/Alcan.IWormFebruary 17, 2006Propagated through file-share networks.
W32/Bolgimo.worm
W32/IRCbot.wormW32/Checkout, W32.Mubla, W32/IRCBot-WB, and Backdoor.Win32.IRCBot.aaqTrojan WormBackdoorJune 1, 2007It provides a backdoor server and allows a remote intruder to gain access and control over the computer via an IRC channel.
WANKOILZOctober 1989Spread a pacifist, anti-nuclear political message.
WelchiaNachia, NachiA helpful worm meant to install security patches and removes Blaster worm if the computer is infected by it.
WittyMarch 19, 2004Appeared very rapidly after announcement of Internet Security Systems vulnerability
ZotobFarid Essebar and Atilla Ekici