|
|
I-Worm.Sexer. Viruses Information
| Name: |
I-Worm.Sexer. |
| Category: |
Viruses |
| Description:
|
Details
I-Worm.Sexer.b
The Sexer.b Internet worm spreads via the Internet as an infected email attachment file named, KAVUtil.exe. The worm's code is written in Delphi, has a file size of 310KB and is compressed with PKLite32.
The infected file contains the following text (in Russian):
Sender address: support@kaspersky.com
Subject: Утилита для выявления и удаления почтового червя I-Worm.Sexer
Message text:
В связи
с появлением в Сети нового почтового червя I-Worm.Sexer предлагаем
Вам утилиту для выявления и удаления этого червя из системы.
Описание I-Worm.Sexer доступно в Вирусной Энциклопедии Касперского по адресу:
http://www.viruslist.com/viruslist.html
file attachment: KAVUtil.exe
The Sexer worm only gains control if the attached file is opened (run).
Spreading
Sexer copies itself to the Program FilesCommon Filessystem directory under the name KAVUtil.exe and then registers itself in the system registry auto-run key with the following entry:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
KAVUtil = kavutil.exe
Sexer then creates the file KAV.bmp in the Program FilesCommon Filessystem directory. The system then installs this file as the desktop background image.
The worm searches the system registry for the key:
SoftwareMicrosoftWABWAB4Wab File Name
Sexer then sends itself out to all the email addresses found in the email client's address book. To physically mail itself, Sexer makes a direct connection with the SMTP server. |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
KeyPress.93
AntiPascal Famil
Plovdiv Famil
TheRa
Trojan.Java.ClassLoader.
ABC.237
Macro.Word.Karatk
Macro.Word.Louvad
Knight.113
I-Worm.FriendMes
|
|