 |
Spyware Warrior Help with Spyware, Hijacking & Other Internet Nuisances
|
| View previous topic :: View next topic |
| Author |
Message |
quietman7 Warrior Addict

Joined: 20 Dec 2004 Last Visit: 28 Mar 2012 Posts: 768 Location: Virginia, USA
|
Posted: Wed Mar 08, 2006 4:52 am Post subject: New IM Worms Delete Files: W32.Maniccum & W32/Hotmatom |
|
|
W32/Hotmatom
1. The worm attempts to lure victims to follow a URL link, in so doing downloading a copy of it, and infecting themselves. It monitors Internet Explorer windows in order to detect when a new message is being created within MSN Hotmail.
2. The worm monitors browser window to detect when MSN hotmail is being used for sending new mail, and inserts text to such messages, which contains a URL from where the worm is downloaded if the recipient clicks on the link.
3. It deletes files on the root of C: and A:, and copies itself there in place of those files, appending a .EXE file extension
http://secunia.com/virus_information/27456/hotmatom/
http://vil.nai.com/vil/content/v_138829.htm
W32.Maniccum is a worm that opens a?back door on the compromised computer?and spreads via AOL and MSN instant messenger.
http://www.sarc.com/avcenter/venc/data/w32.maniccum.html
Closes?windows?that start with the following strings:
* NORTON
* VIRUS
* FIREWALL
* SCAN
* SECURITY
* NETSTAT
* WINDOWS TASK MANAGER
* THE ETHEREAL NETWORK ANALYZER
* REGISTRY EDITOR
* SYSTEM CONFIGURATION UTILITY _________________ Microsoft MVP - Consumer Security 2007-2012
Member of UNITE, Unified Network of Instructors and Trusted Eliminators |
|
| Back to top |
|
 |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
smartBlue Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group
|