This application requires Javascript for optimal performance.

W32/Kelvir.A!worm.im - Released Mar 07, 2005 - Last Updated Mar 11, 2005

Alias/es

W32/Kelvir!wm, W32/Kelvir.A-net, W32/Kelvir.A-tr, W32/Kelvir.BP-net

Detection Availability

Active DatabaseExtended Database
FortiGate
low
high
FortiClient
FortiMail N/A

Visible Symptoms

  • On strict configured systems, firewall applications may alert of "Windows Messenger API" is attempting to access the Internet using TCP port 127.0.0.1

  • Possible connection attempt to the website 'home.comcast.net'

Detailed Analysis

This 32-bit threat is an Internet worm designed to manipulate MSN Messenger in order to distribute itself to contacts found in the Messenger contact list. This threat attempts to download a copy of itself from a Comcast.net user account as the file "patch.exe". The file is not available at the time of this writing.

Recommended Action

Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option

Reference: ID - 166991