Sophos

W32/Braid-A

Aliases
  • PE_BRID
  • W32/Braid@MM
  • I-worm.Bridex
  • Win32/Brid.A
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from January 2003 (3.65)
Detected by All Sophos products

Action

Please read the instructions for disinfecting W32/Braid-A.

More Information

W32/Braid-A is an internet worm which emails itself to every contact in the Microsoft Outlook address book.

The worm attempts to exploit a MIME and an IFRAME vulnerability in some versions of Microsoft Outlook, Microsoft Outlook Express, and Internet Explorer. These vulnerabilities allow an executable attachment to run automatically, even if you do not double-click on the attachment. Microsoft has issued a patch which secures against these attacks. The patch can be downloaded from Microsoft Security Bulletin MS01-027. (This patch was released to fix a number of vulnerabilities in Microsoft's software, including the ones exploited by this worm.)

When the worm is first run it copies itself to the Desktop as Explorer.exe, to the System folder as Regedit.exe and creates the registry entry

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\regedit = C:\WINDOWS\SYSTEM\regedit.exe

so that this file is run automatically each time the computer is restarted.

The worm drops W32/Flcss to the System folder as Bride.exe. Bride.exe is then launched whenever another executable is run.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer