W32/Kelvir.A!worm.im - Released Mar 07, 2005 - Last Updated Mar 11, 2005
|
Alias/esW32/Kelvir!wm, W32/Kelvir.A-net, W32/Kelvir.A-tr, W32/Kelvir.BP-net |
Detection Availability
|
Visible Symptoms- On strict configured systems, firewall applications may alert of "Windows Messenger API" is attempting to access the Internet using TCP port 127.0.0.1
- Possible connection attempt to the website 'home.comcast.net'
|
Detailed AnalysisThis 32-bit threat is an Internet worm designed to manipulate MSN Messenger in order to distribute itself to contacts found in the Messenger contact list. This threat attempts to download a copy of itself from a Comcast.net user account as the file "patch.exe". The file is not available at the time of this writing. |
Recommended ActionCheck the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option
|