W32/Nofer-A

Discussion in 'malware problems & news' started by Technodrome, Jun 16, 2003.

Thread Status:
Not open for further replies.
  1. Technodrome

    Technodrome Security Expert

    Joined:
    Feb 13, 2002
    Posts:
    2,140
    Location:
    New York
    Aliases:
    I-Worm.Fearso, Win32/Farex.A, PE_NOFEAR.A, W32/Nofer.A@mm, W95/Fearso.A@mm

    At the time of writing Sophos has received no reports from users affected by this worm. However, we have issued this advisory following enquiries to our support department from customers.


    W32/Nofer-A is an internet worm that will attempt to email itself to addresses
    found from a variety of sources on the local machine. W32/Nofer-A will also try to infect executable files.

    W32/Nofer-A will copy itself to svchost.exe and to a randomly named executable file in the Windows folder. It creates a registry entry in

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\

    that points to the randomly named executable file to ensure the worm is run at system startup.

    W32/Nofer-A will also attempt to spread using peer-to-peer networks.

    http://www.sophos.com



    tECHNODROME
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.