Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Please read the instructions for disinfecting W32/Braid-A.
More Information
W32/Braid-A is an internet worm which emails itself to every contact in the Microsoft Outlook address book.
The worm attempts to exploit a MIME and an IFRAME vulnerability in some versions of Microsoft Outlook, Microsoft Outlook Express, and Internet Explorer. These vulnerabilities allow an executable attachment to run automatically, even if you do not double-click on the attachment. Microsoft has issued a patch which secures against these attacks. The patch can be downloaded from Microsoft Security Bulletin MS01-027. (This patch was released to fix a number of vulnerabilities in Microsoft's software, including the ones exploited by this worm.)
When the worm is first run it copies itself to the Desktop as Explorer.exe, to the System folder as Regedit.exe and creates the registry entry
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\regedit = C:\WINDOWS\SYSTEM\regedit.exe
so that this file is run automatically each time the computer is restarted.
The worm drops W32/Flcss to the System folder as Bride.exe. Bride.exe is then launched whenever another executable is run.
