W32/Nofer-A

Discussion in 'malware problems & news' started by Technodrome, Jun 16, 2003.

Thread Status:
Not open for further replies.
  1. Technodrome

    Technodrome Security Expert

    Joined:
    Feb 13, 2002
    Posts:
    2,140
    Location:
    New York
    Aliases:
    I-Worm.Fearso, Win32/Farex.A, PE_NOFEAR.A, W32/Nofer.A@mm, W95/Fearso.A@mm

    At the time of writing Sophos has received no reports from users affected by this worm. However, we have issued this advisory following enquiries to our support department from customers.


    W32/Nofer-A is an internet worm that will attempt to email itself to addresses
    found from a variety of sources on the local machine. W32/Nofer-A will also try to infect executable files.

    W32/Nofer-A will copy itself to svchost.exe and to a randomly named executable file in the Windows folder. It creates a registry entry in

    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\

    that points to the randomly named executable file to ensure the worm is run at system startup.

    W32/Nofer-A will also attempt to spread using peer-to-peer networks.

    http://www.sophos.com



    tECHNODROME
     
Thread Status:
Not open for further replies.