The Web    Google
3/30: Kelvir-F IM Worm Sends Message

3/30: Kelvir-F IM Worm Sends Message
March 30, 2005

W32/Kelvir-F is an instant messaging worm that spreads by sending a message through Windows Messenger to all of an infected user's contacts. W32/Kelvir-F arrives attached to a message that encourages the recipient to visit a web page to download a file.

At the time of writing, the file at the URL is named funnyashell.scr and is detected by Sophos's anti-virus products as W32/Rbot-ZU.

More information can be found at Sophos page.

  • 3/16: Trojan.Alpiok Modifies Hosts File
  • 3/29: Krynos-B Worm Drops Copy of Itself
  • 3/4: Rbot-WV Worm Uses Bad Passwords
  • More Fortification For Code
  • SunGard to Spin Off Disaster Recovery Biz
  • 3/25: Sdbot-WG a Worm and IRC Trojan
  • 2/17: Rbot-WB Worm Has Trojan Functions
  • Netsky-C Hammers U.S. and U.K.
  • Biometrics Makes Passwords Positively Paltry
  • 2/23: Anicmoo-B a Downloader Trojan
  • WIDCOMM Bluetooth a Virus Risk
  • Security Camera Companies and products