The Web    Google
4/29: Kelvir-D an IM Worm

4/29: Kelvir-D an IM Worm
April 29, 2005

W32/Kelvir-D is an instant messenging worm that spreads by sending a message through Windows Messenger to all of an infected user's contacts.

W32/Kelvir-D arrives attached to the message that encourages the recipient to visit a web page to download an update and reads:

lol! see it! u'll like it.

W32/Kelvir-D also attempts to download and execute ME.JPG and FILE.EXE files from the predefined websites.

The ME.JPG file is detected by Sophos as W32/Rbot-XA.

More information can be found at Sophos page.

  • 'Critical' Office 2003 Patch Released
  • Wi-Fi Planet Toronto: Security Taking Hold
  • 3/11: Rbot-XM Worm Hits Remote Shares
  • CERT: Sendmail Hacked
  • Asita, RapidStream offer up high-capacity VPN wares
  • Securiant Aims Appliance at Small, Medium Businesses
  • A Pattern Language For Spam
  • CERT, ArcSight Partner With 3 Universities On Security Sharing
  • Security Objections to IBM-Lenovo Deal?
  • 1/27: Rbot-AIX Worm Has Backdoor Functions
  • OpenVMS: An Old OS Hasn't Lost Security Footing
  • Home Security Camera Background