Summary

Summary
Action
More Information
| Protection available since | 2 January 2004 10:53:22 (GMT) |
|---|---|
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Change any data that may have become compromised.
You will also need to edit the following registry entries, if they are present. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MSFind32
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\MSFind32
and delete them if they exist.
Close the registry editor.
More Information
W32/Cayam-A is a worm that attempts to spread via email and common file sharing networks.
In order to run automatically when Windows starts up the worm copies itself to the file msfind32.exe in the Windows folder and adds the following registry entries pointing to this file:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MSFind32
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\MSFind32
To spread via filesharing networks the worm copies itself to
C:\Program Files\KazAa\My Shared Folder\Mayacrack.exe and
C:\Program Files\eMule\Incoming\3dsmaxcrack.exe.
W32/Cayam-A also copies itself to the file C:\eBayVerify.exe.
The worm attempts to spread via email by sending this file attached to a HTML email message containing the following text:
"Dear valued eBay member, It has come to our attention that your eBay Billing Information records are out of date. That requires you to update the Billing Information If you could please take 5-10 minutes out of your online experience and update your billing records, you will not run into any future problems with eBay's online service. However, failure to update your records will result in account termination. Please update your records in maximum 24 hours. Once you have updated your account records, your eBay session will not be interrupted and will continue as normal. Failure to update will result in cancellation of service, Terms of Service (TOS) violations or future billing problems.
Please open attachment to update your billing records.
The worm attempts to steal credit card numbers and eBay account passwords by displaying a bogus eBay dialog window prompting the user to enter their address, credit card and eBay account information.
Due to a programing error the email is usually not sent and an empty Window "Demo of Outlook control" is displayed.
