|







|
|
Top 10 malware reported to Sophos in November 2002
This section helps you to understand how it behaves
W32/Braid-A is an internet worm which emails itself to every contact in the
Microsoft Outlook address book.
The worm attempts to exploit a MIME and an IFRAME vulnerability in some
versions of Microsoft Outlook, Microsoft Outlook Express, and Internet
Explorer. These vulnerabilities allow an executable attachment to run
automatically, even if you do not double-click on the attachment. Microsoft
has issued a patch which secures against these attacks. The patch can be
downloaded from Microsoft Security Bulletin MS01-027. (This patch was
released to fix a number of vulnerabilities in Microsoft's software,
including the ones exploited by this worm.)
When the worm is first run it copies itself to the Desktop as Explorer.exe,
to the System folder as Regedit.exe and creates the registry entry
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\regedit =
C:\WINDOWS\SYSTEM\regedit.exe
so that this file is run automatically each time the computer is restarted.
The worm drops W32/Flcss to the System folder as Bride.exe. Bride.exe is
then launched whenever another executable is run.
|
|
|
This web is optimized for 800 x 600 monitor resolution or above and
the latest web browser. Get the latest IE or Netscape web browser. (you
need to connect to the internet first) |
|
|