Sophos

W32/Cailont-B

Aliases
  • W32.Nolor.B@mm
Category
Type
What to do
Prevalence low high

Summary

 
Protection available since 28 September 2003 09:47:22 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Cailont-B is an email aware worm.

The subject line, message text and attachment filename of the email are produced by concatenating several randomly chosen phrases.

The email contains an HTML component which itself contains a Visual Basic Script which drops and runs W32/Cailont-B.

When run W32/Cailont-B copies itself to various folders on the system which may include:

C:\Program Files\Microsoft Office\Office\startup
C:\Windows\System\viewers
C:\Windows\All Users\Start Menu\Programs\Startip
C:\Windows\Start Menu\Programs\StartUp
C:\Windows\System

W32/Cailont-B will also drop the Visual Basic Script version of itself in one or more files with a DAT extension. These files are detected as VBS/Cailont-A.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer