The Web    www.100share.com    Google
 
3/7: Kelvir-B an Instant Messaging Worm
 

3/7: Kelvir-B an Instant Messaging Worm
March 7, 2005

Several vendors have issued alerts for W32/Kelvir-B, an instant messenging worm. It spreads by sending a message through Windows Messenger to all of an infected user's contacts. The message encourages the recipient to visit a web page to download an update and reads:

omg this is funny!

W32/Kelvir-B will attempt to download a file named PATCH.EXE from a remote website and save it as C:\patch.exe

More information can be found at Sophos page.

W32.Kelvir.B is a worm that spreads through Windows Messenger and MSN Messenger and attempts to download and execute a variant of W32.Spybot.Worm, according to Symantec.

Technical details can be found at this Symantec page.

According to McAfee, which also issued an alert, W32/Kelvir.worm.b spreads via MSN Messenger. Contact List recipients:

omg this is funny! http:// {blocked}.home.att.net/cute.pif
note: the actual address has been blocked here to prevent infection.

Following the hyperlink in the email messages may result in the worm file being downloaded and subsequently executed by the user. Once infected, the worm may also attempt to download a new W32/Sdbot.worm variant from the following site:

http://home.comcast.net/ {blocked}/patch.exe

note: the actual address has been blocked here to prevent infection.

More information can be found at this McAfee page.

Trend Micro has declared a medium risk alert to control the spread of Worm_Kelvr.B, a new Kelvir variant that is currently spreading in Korea and the United States.

This memory-resident worm spreads copies of itself via MSN Messenger, a popular instant messaging application. It attempts to send an instant message to all the MSN messenger contacts of an affected user that are online. This message contains a URL that downloads a copy of this worm into a system.

This file then downloads and executes malicious files from the following Web sites: http://home.earthnk.net/~gallery10/me.jpg
http://www.yourte.com/file.exe
The downloaded file, ME.JPG, is detected by Trend Micro as Worm_Sdbot.Auk.

Technical details can be found at this Trend Micro page.


 
  • Trolling For Anti-Phishing Laws
  • Can Market Forces Secure the Internet?
  • Jenny Craig Goes on a No-Spam Diet
  • Deceptive Duo Hacker Changes Plea
  • 8/2: MyDoom-P Sends Spoofed Emails
  • SunGard to Spin Off Disaster Recovery Biz
  • Information Theft Reaches Estimated $59 Billion
  • 4/18: Mytob-BR Worm Mails Itself Out
  • 9/3: Worm Ends Antivirus Processes
  • Startup Unveils Web Server Assessment, Defense Toolkit
  • Biometric Security - From Fingers To Faces
  • Security Camera News