The W32/CEP.worm is designed to spread via the removable media and drops BackDoor-CEP trojan.
|
Minimum DAT
5121 (2007-09-17) Updated DAT5558 (2009-03-19) |
Minimum Engine
4.4.00 File Length229,376 bytes |
Description Added
2007-09-17 Description Modified2007-09-26 |
Upon execution, the worm copies itself to the following location.
It drops the following files:
The worm adds the following registry key.
The dropped BackDoor-CEP trojan adds the following registry keys:
The BackDoor-CEP trojan attempts to connect the following remote site and waits commands.
The worm attemps to drop the following files into the removable drives:
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
But in some particular cases, the following steps need to be taken.
Please go to the Microsoft Recovery Console and restore a clean MBR.
On Windows XP:
On Windows Vista and 7: