White Papers

W32/GOP-A / W32.HLLW.GOP / IMEKERNEL32

Overview Date: Fri, 4 Jan 2002 17:57:39 (GMT)

Name: W32/GOP-A

Aliases: W32.HLLW.GOP

Type: Win32 worm

Description: W32/GOP-A is a password stealing email-aware Windows 32 worm.

The worm typically arrives as an email attachment with a double extension (for instance, .txt.exe, .jpg.exe or .doc.exe) in an attempt to disguise that it is an executable file.

When the attachment is launched, it creates the files IMEKernel32.sys and kernelsys32.exe in the Windows system folder. It also adds the registry value IMEKERNEL32 to
HKLM\Software\Microsoft\Windows\CurrentVersion\Run.

The worm attempts to spread via email and to steal ICQ passwords.

Click through to view the alert text for disinfection information.

Further White Paper Details
PublisherSophos File FormatHTML
Date PublishedJanuary 2002
FormatWhite Papers   
Topics
    N/A
Thin clients switch on digitally excluded

Thin clients switch on digitally excluded

Case study: Digital inclusion project tackles social exclusion in Liverpool more

Renault goes multilingual

Renault goes multilingual

Case study: Translation tech turns docs into 23 languages… more


Quick Sitemap Links: