TrendMicro: WORM_KELVIR.N

Discussion in 'malware problems & news' started by Randy_Bell, Apr 15, 2005.

Thread Status:
Not open for further replies.
  1. Randy_Bell

    Randy_Bell Registered Member

    Joined:
    May 24, 2002
    Posts:
    3,004
    Location:
    Santa Clara, CA
    WORM_KELVIR.N is a non-destructive worm that propagates via MSN Messenger. It send a message to all contacts listed in the affected user's MSN Messenger Contacts, with a link. When clicked, this link downloads a file. This worm is currently spreading in-the-wild and infecting computers running Windows 95, 98, ME, NT, 2000, and XP.

    Upon arrival, this worm drops, extracts, and executes the following files:

    * UNCANNY.EXE – a copy of the worm
    * ADVBOT.EXE – Trend Micro detects this as WORM_SDBOT.BLL

    This worm sends a message to all contacts in MSN Messenger with the following details:

    Once the recipient clicks the link, the file ADVBOT.EXE is downloaded, which Trend detects as WORM_SDBOT.BLL.

    If you would like to scan your computer for WORM_KELVIR.N or thousands of other worms, viruses, Trojans and malicious code, visit HouseCall, Trend Micro's free, online virus scanner at: http://housecall.trendmicro.com/

    WORM_KELVIR.N is detected and cleaned by Trend Micro pattern file #2.566.00 and above.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.