Sophos

W32/Kelvir-BC

Aliases
  • Trojan-Downloader.Win32.Agent.aae
  • W32/Kelvir.worm.gen
  • WORM_KELVIR.CX
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Chat programs
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 25 November 2005 09:56:19 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Kelvir-BC is a worm for the Windows platform.

W32/Kelvir-BC can spread via MSN Messenger. W32/Kelvir-BC will send one of the following messages to the contacts of an infected computer, accompanied with a link to the worm:

"naaao sam tvoju sliku"
"naael jsem tvoji fotku!"
"jeg fandt dit billede"
"ik vond uw foto"
"I found your photo"
"Leysin kuvasi"
"J'ai trouve votre photo"
"Ich hab dein Foto gefunden"
"brhka th foto sou"
"ho trovato la tua fotografia"
"Jeg fant bildet ditt"
"znalazlem twoje zdjecie"
"encontrei sua foto"
"ti-am gasit poza"
"encontre su fotograf"
"Jag hittade ett foto po dig"
"Resmini buldum"

W32/Kelvir-BC includes functionality to access the internet and communicate with a remote server via HTTP.

W32/Kelvir-BC may also attempt to disable the Windows Task Manager, Registry editor, and System Restore.

When first run W32/Kelvir-BC copies itself to <System>\nkn.exe and creates the file \NotKelvir.exe.

The following registry entry is created to run nkn.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
MSN Service Utilities
nkn.exe

The following registry entry is set:

HKLM\SOFTWARE\NotKelvir
OriginalPath
<pathname of the Trojan executable>

Registry entries are created under:

HKLM\SOFTWARE\NotKelvir\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer