TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_GOP.F
Overview

Malware type: Worm

Aliases: W32/Wangy.gen@MM (McAfee), W32.HLLW.Wangy@mm (Symantec), Worm/Wangy.A (Avira), W32/Wangy-A (Sophos),

In the wild: No

Destructive: No

Language: English

Platform: Windows

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Description: 

This worm propagates via email and network shares. It sends the following email with itself as attachment to all addresses listed in the infected user's Microsoft Outlook address book:

Subject: <Chinese characters>
Message Body: <Chinese characters>
Attachment: photo.gif.exe

It drops a copy of itself as QQ2002.exe in network-shared drives and folders with read and write access.

This worm steals the OICQ (Chinese version of ICQ) passwords of infected systems. It sends the stolen information to a specific email address.

For additional information about this threat, see:
Solution
Technical Details

Description created: Nov. 29, 2002 11:47:19 AM GMT -0800
Description updated: Apr. 3, 2005 11:31:49 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.