|
Detection files published:
18 Apr 2001 |
Description created:
2001-04-18 |
Description updated:
2001-04-18 |
|
Alias:
|
Spreading mechanism
| |
|
Payload:
| ||
It installs itself in the registry under the key
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run (default) =\MATCHER.EXE
so that the worm is run every time the machine starts. An additional effect is that the following lines are inserted into the AUTOEXEC.BAT file:
@echo off
echo from: Bugger
pause
Thus, machines infected with this worm will show the message from: Buggeron the screen during startup and wait for the user to press a key. Since the worm is started every time the computer is started, this message can be entered repeatedly into AUTOEXEC.BAT.
Norman's antivirus products are in general able to remove all malicious software that is detected.
Some malware, however, uses techniques that the general product does not remove sufficiantly. We have therefore developed the free product Norman Malware Cleaner. Please use the latest version of this program from the link below - if your Norman antivirus is unable to clean-up the infection.
| Usage | Title | Comment |
|---|---|---|
| Stopping network share infectors | ||
| Cleaning of back-up folders on Windows Me and XP |