W32/Matcher@mm.28672
W32/Matcher@mm.28672
Threat risk
|
Detection files published:
18 Apr 2001 |
Description created:
2001-04-18 |
Description updated:
2001-04-18 |
|
Alias:
|
Spreading mechanism
| |
|
Payload:
| ||
Spreading description
Email characteristics:
Subject: Matcher
Body: Want to find your love mates!!! Try this its cool... Looks and Attitude Maching to opposite sex.
Attachment: matcher.exe
Threat description
It installs itself in the registry under the key
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run (default) =\MATCHER.EXE
so that the worm is run every time the machine starts. An additional effect is that the following lines are inserted into the AUTOEXEC.BAT file:
@echo off
echo from: Bugger
pause
Thus, machines infected with this worm will show the message from: Buggeron the screen during startup and wait for the user to press a key. Since the worm is started every time the computer is started, this message can be entered repeatedly into AUTOEXEC.BAT.
Removal
General information about removal of malicious software
Norman's antivirus products are in general able to remove all malicious software that is detected.
Some malware, however, uses techniques that the general product does not remove sufficiantly. We have therefore developed the free product Norman Malware Cleaner. Please use the latest version of this program from the link below - if your Norman antivirus is unable to clean-up the infection.
| Utilizzo | Titolo | Commento |
|---|---|---|
| Blocco dei virus che infettano le condivisioni di rete | ||
| Cleaning of back-up folders on Windows Me and XP |
