|
|
311 ICQ worm Worm Information
| Name: |
311 ICQ worm |
| Category: |
Worm |
| Alias: |
- Alias: I-Worm.Lee.d, I-Worm.Lee.e, I-Worm.Lee.f |
| Advice: |
Remove |
| Risk: |
Severe Risk
Severe threats typically are remotely exploitable vulnerabilities, which can lead to system compromise. Successful exploitation does not normally require any interaction and exploits are in the wild. There exists a high possibility of potential system damage or security flaw. Attacker has complete control over your computer or install new software on your machine. |
| Description:
|
311 is an ICQ based worm that spread to ICQ users giving remote access to the infected user's computer.
The worm, which makes use of breaches in Microsoft Windows and Internet Explorer, spreads by sending an instant message to ICQ users that includes a link to the www.jokeworld.biz Web site. When a user visits the site, it shows what appears to be an innocuous cartoon but in the background replicates the worm onto the user's machine.
|
| Signatures:
|
process: 311icq.exe: MD5 Hash: 2cfcad6359293f3133d.. |
| Type: |
Worm - A worm is program that propagates by attacking other computers and copying itself to them. Worms may replace files, but do not insert themselves into files (as viruses do). |
Top Worm Visited Pages:
Wukill.mstray - Alias: Win32/HLLW.Wukill - 294 visits
Rbot - Alias: Backdoor.Rbot.Gen - 276 visits
SDBot - Alias: Wootbot.gen, Wootbot, Donk, spybot, Agobot - 229 visits
Trojan.Downloader.winstall - 182 visits
Worm.Brit.e - Alias: VBS/Chick.e@M virus - 89 visits
Worm.P2P.SpyBot.gen - 56 visits
Gaobot - 44 visits
Win32/Darby.O - 42 visits
Worm.Trilissa.e - 42 visits
JS.Lame - Alias: HTML.Lame - 40 visits
Random Worm Pages:
Greetings
VBS.Voodoo - Alias: DNet.a, W32/Bymer.B
IRC.Worm.Simona.a
Worm.Happytime.a
Virus.Leave.A Worm - Alias: I-Worm.Leave, W32/Leave.worm.gen
Worm.P2P.Herpes
Rbot.P3 - Alias: Backdoor:Win32/Rbot
Vbasic.5120.E - Alias: Vbasic.c
Virus.Gizer.a@MM - Alias: I-Worm.Gizer.a
Independance Day - Alias: I-Worm.Lee.d, I-Worm.Lee.e, I-Worm.Lee.f
|
|