Skip to main content
Microsoft Security Intelligence
Published Dec 22, 2008 | Updated Sep 15, 2017


Detected by Microsoft Defender Antivirus

Aliases: W32.Spybot.Worm (Symantec) W32/Checkout (McAfee) Backdoor.Win32.Rbot.gxp (Kaspersky)


Worm:Win32/Pushbot.CC is a worm that may spread via MSN Messenger and/or AIM. The worm also contains backdoor functionality that allows unauthorized access to an affected machine. This worm does not spread automatically upon installation, but must be ordered to spread by a remote attacker.
Manual removal is not recommended for this threat. To detect and remove this threat and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner ( For more information, see
Follow us