WORM_SOHANAD.AC
Overview

QUICK LINKS  

Understanding New Pattern Format |

Malware type: Worm

Aliases: Trojan:Win32/Malagent (Microsoft)

In the wild: Yes

Destructive: No

Language: English

Platform: Windows 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:

Low

Reported infections:

Low

Damage potential:

High

Distribution potential:

High

Infection Channel 1 : Propagates via instant messaging applications


Description: 

To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.

WORM_SOHANAD.AC Behavior Diagram

Malware Overview

This worm propagates via instant messaging applications. It sends an instant message to all contacts of an affected user. The said message contains a link that when accessed, downloads and executes a copy of this worm.

It creates related registry entries to disable Registry Editor and Task Manager. By disabling both applications, this worm avoids easy detection and removal. It also modifies the settings of Yahoo! Messenger.

It changes the Internet Explorer (IE) title bar by modifying related registry entry. It also prevents manual modification of the IE home page by creating a related registry entry.

This worm also downloads a copy of itself from certain URLs. As a result, its copy is always present on the affected system.

For additional information about this threat, see:
Solution
Technical Details
Statistics

Description created: Nov. 1, 2006 4:43:33 AM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.

Quick Links