Virus:Email-Worm.Win32.Warezov.ndOther versions: .at , .bw , .do , .et, .ex, .gl, .iq, .jv, .jx, .la, .lb, .lg, .ms, .mx, .nf , .ns , .nv , .oa , .oi
This worm is a Windows PE EXE file. It is 90,304 bytes in size. It is packed using Upack. The unpacked file is approximately 237KB in size. InstallationWhen launched, the worm creates the following files: %System%\shfoxpob.dat%System%\shfoxpob.exe %System%\shfoxpob.dll The worm also creates the following system registry key: [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\shfoxpob]"DllName" = "%System%\shfoxpob.dll" "Startup" = "WlxStartupEvent" "Shutdown" = "WlxShutdownEvent" "Impersonate" = dword:00000000 " Asynchronous" = dword:00000000 PropagationThis worm spreads via ICQ messages. Messages read "Check this::" followed by the link shown below: http://******adfesunkawunsa.com/1/853/If the user opens this link in the browser, s/he will be asked if s/he wants to download and launch a file called "archive.exe", which is the latest version of the worm.
The worm will disable a range of antivirus and firewall applications. The worm is also about to download other malicious programs from the remote malicious user's site, and launch them for execution on the victim machine.
Îáíàðóæåíèå. Detection for this version of the worm was added to the Kaspersky Anti-Virus databases as an urgent update. If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:
|
|||||||||||