VIRUS NAME : W32/Enemany.a.intd
Virus Characteristics
This threat is detected as New Malware, New BackDoor, or New Worm with the 4150 DATs, or newer, when running with program heuristics enabled. Avert has yet to receive a field sample of this worm. The 4206 DATs will detect this as W32/Enemany.gen@MM.
This is an intended mass-mailing worm. However, due to a typo in the code, messages sent by this worm do not contain the intended attachment. When run, a message box is displayed.
All addresses found in the Microsoft Outlook Address book are sent a message with the following information:
Subject: The New Xerox Update for our WinXP
Body:
Dear, Microsoft WinXP User, here are the last Update from Xerox Security System, please install this file and going to www.microsoft.com and finished this Update too.
The worm fails to function properly as the program attempts to attach the file, Xerox-Update.Exe.exe. However, this file is not created by the worm.
Symptoms
The virus copies itself to the following locations:
c:\WINDOWS\SYSTEM\Ati.scr
c:\WINDOWS\Xerox-Update.Exe
c:\WINDOWS\Start Menu\Programs\StartUp\WinUpdate.exe
Method Of Infection
N/A This is an intended virus that does not propagate as intended.
|