Sophos

W32/GetCodec-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Included in our products from October 2008 (4.34)
Protection available since 17 July 2008 06:42:35 (GMT)
Last updated 4 September 2008 04:50:20 (GMT)
Detected by All Sophos products

Action

More Information

W32/GetCodec-A is a worm for the Windows platform.

When run, the worm sets the following registry entries:

HKCU\Software\Microsoft\PIMSRV\

HKCU\Software\Microsoft\MediaPlayer\Preferences\
URLAndExitCommandsEnabled
0

HKCU\Software\Microsoft\MediaPlayer\Player\Extensions\.mp3\
Permissions
33

The worm has the functionalities to:

 - Search the infected computer for files with the extension of .mp3, .wmv, .wma .mp2 and .mp3
- Convert the located files to wma format without modifying the original filename and extension
- Insert the functionality to download code from a remote website into the converted wma format files.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer