Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | March 2006 (4.03) |
| Protection available since | 25 January 2006 07:44:11 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Fasong-I is a worm for the Windows platform.
W32/Fasong-I will search the list of running processes, and may create copies of itself in random locations, possibly including network shares, using the names of active processes it finds.
W32/Fasong-I may also drop a DLL component into a random location with a random name. This DLL is detected as W32/Fasong-H.
W32/Fasong-I contains an SMTP engine which it may use to send itself by email. W32/Fasong-I is a worm for the Windows platform.
W32/Fasong-I will search the list of running processes, and may create copies of itself in random locations, possibly including network shares, using the names of active processes it finds.
W32/Fasong-I may also drop a DLL component into a random location with a random name. This DLL is detected as W32/Fasong-H.
W32/Fasong-I contains an SMTP engine which it may use to send itself by email.
When W32/Fasong-I is installed the following non-infected file is created :
\filedebug
This is an ASCII file containing a numerical string.
Registry entries are created under:
HKCR\BFWorkFile1007PV\
