The Web    Google
4/29: Kelvir-D an IM Worm

4/29: Kelvir-D an IM Worm
April 29, 2005

W32/Kelvir-D is an instant messenging worm that spreads by sending a message through Windows Messenger to all of an infected user's contacts.

W32/Kelvir-D arrives attached to the message that encourages the recipient to visit a web page to download an update and reads:

lol! see it! u'll like it.

W32/Kelvir-D also attempts to download and execute ME.JPG and FILE.EXE files from the predefined websites.

The ME.JPG file is detected by Sophos as W32/Rbot-XA.

More information can be found at Sophos page.

  • 3/25: Sdbot-WG a Worm and IRC Trojan
  • 9/9: BackDoor-CEB.C Remote Access Trojan
  • 1/5: Rbot-SQ Worm Has Backdoor Abilities
  • Netsky-P a Year Old and Going Strong
  • Disaster Recovery Vs. Business Continuity
  • 11/29: QLowZones-2 Modifies IE Settings
  • How Long Must You Wait for an Anti-Virus Fix?
  • Sigaba Adds Federated Authentication to E-Mail Security Software
  • Report: IT Security Begins at the Top
  • 5/13: Sqdrop-A a Dropper Trojan
  • Virus Alert: New Worm Spreads Through KaZaA, IRC
  • Cheap Security Camera