Sophos

W32/Fasong-I

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email messages
  • Network shares
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from March 2006 (4.03)
Protection available since 25 January 2006 07:44:11 (GMT)
Detected by All Sophos products

Action

More Information

W32/Fasong-I is a worm for the Windows platform.

W32/Fasong-I will search the list of running processes, and may create copies of itself in random locations, possibly including network shares, using the names of active processes it finds.

W32/Fasong-I may also drop a DLL component into a random location with a random name. This DLL is detected as W32/Fasong-H.

W32/Fasong-I contains an SMTP engine which it may use to send itself by email. W32/Fasong-I is a worm for the Windows platform.

W32/Fasong-I will search the list of running processes, and may create copies of itself in random locations, possibly including network shares, using the names of active processes it finds.

W32/Fasong-I may also drop a DLL component into a random location with a random name. This DLL is detected as W32/Fasong-H.

W32/Fasong-I contains an SMTP engine which it may use to send itself by email.

When W32/Fasong-I is installed the following non-infected file is created :

\filedebug

This is an ASCII file containing a numerical string.

Registry entries are created under:

HKCR\BFWorkFile1007PV\

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer