This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
|
Minimum DAT
4284 (2003-08-11) Updated DAT4284 (2003-08-11) |
Minimum Engine
5.1.00 File Length18,432 bytes |
Description Added
2003-09-04 Description Modified2003-11-10 |
This threat is deemed Low-Profiled due to media attention at http://www.theregister.co.uk/content/56/32662.html
McAfee users are proactively protected from this threat when scanning with the 4252 DAT files, compressed executables, and the 4.2.40 scan engine. 4.1.60 engine users are also protected under the same scenario, but also require program heuristics. The detection name varies with DAT file version and engine, and will be along the lines of W32/Generic or New Worm.
The virus is detected as W32/Generic.worm!irc This worm attempts to spread via Microsoft Outlook, and Internet Relay Chat. The worm also terminates security software, contains a Denial of Service attack payload, a web page overwriting payload, and disables the registry editor and task manager. The virus may be received in an email message as follows:
Followed by
Followed by
For example:
When the attachment is run (manually accessed with the mouse or keyboard), the virus attempts to copy itself to the PROGRA~1 (Program Files) directory as ACCOUNT_DETAILS.DOC.exe. This failed during testing. A registry key is created to load this, non-existent, file:
The virus terminates the following processes:
The virus attempts to stop the following services:
This virus spreads via Microsoft Outlook (by sending itself to Outlook Address Book recipients) and the mIRC Internet Relay Chat client.
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
But in some particular cases, the following steps need to be taken.
Please go to the Microsoft Recovery Console and restore a clean MBR.
On Windows XP:
On Windows Vista and 7: