The first time that Duload is run, it copies itself to the Windows system directory under the name "Systemconfig.exe", and edits the system registry so that it is automatically run whenever Windows is loaded.
Once activated the Palyh worm copies itself into the Windows directory under the name "MSCCN32.EXE" and registers this file in the system registry's auto-run key so that it is placed into system memory and automatically launched upon operating...
A variant of the Sobig worm appeared over the weekend and is now spreading rapidly. The attachment is called "document.pif", "screensaver.scr" or another similar name, using a .pif, .txt or .scr extension.
In reality, the program is spreading quite successfully as a Zip-compressed email attachment. The malicious program is contained in an 80KB attachment to the message. It infects any PC running a Microsoft Windows operating system when the...
Schmugar said one of the more unusual aspects of the worm - which McAfee classified as a "moderate" threat - was its use of a Zip file, which could prove to have longer legs than the .exe files most worms try to spread.
The body of the email contains a variety of messages, and the attachment will normally have a double-file name or be a zip file. The worm does require the user to open the attachment with the email. Email management company MessageLabs claims to...