Summary

Summary
Action
More Information
| Protection available since | 28 September 2003 09:47:22 (GMT) |
|---|---|
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Please follow the instructions for removing worms.
More Information
W32/Cailont-B is an email aware worm.
The subject line, message text and attachment filename of the email are produced by concatenating several randomly chosen phrases.
The email contains an HTML component which itself contains a Visual Basic Script which drops and runs W32/Cailont-B.
When run W32/Cailont-B copies itself to various folders on the system which may include:
C:\Program Files\Microsoft Office\Office\startup
C:\Windows\System\viewers
C:\Windows\All Users\Start Menu\Programs\Startip
C:\Windows\Start Menu\Programs\StartUp
C:\Windows\System
W32/Cailont-B will also drop the Visual Basic Script version of itself in one or more files with a DAT extension. These files are detected as VBS/Cailont-A.
