W32/Nahata-F

Discussion in 'malware problems & news' started by FanJ, Jul 8, 2002.

Thread Status:
Not open for further replies.
  1. FanJ

    FanJ Guest

    Name: W32/Nahata-F
    Aliases: I-Worm.Nahata.e
    Type: Win32 worm
    Date: 8 July 2002


    At the time of writing Sophos has received no reports from users
    affected by this worm. However, we have issued this advisory
    following enquiries to our support department from customers.

    Description
    W32/Nahata-F is an intended worm that tries to spread via email, mIRC and Pirch. It drops itself into the root folder of drive C:. It also attempts to drop the file C:\info.vbs.

    Info.vbs should send the worm to email addresses found in the Outlook address book and overwrite script.ini and events.ini when the computer is restarted. However, it does not work properly. The file info.vbs is already detected by Sophos Anti-Virus as VBS/Cuartel-A.



    More information about W32/Nahata-F can be found at
    http://www.sophos.com/virusinfo/analyses/w32nahataf.html
     
Thread Status:
Not open for further replies.