The worm spreads through MSN messengers. When the user launches the worm, it will drop itself into the C:\ directory under one of the following names. Drunk_lol.pif love_me.pif naked_party.pif sexy_bedroom.pif Webcam_004.pif It will also drop Backdoor.Win32.rbotfly into the Windows directory. adaware.exe lexplore.exe VB6.EXE Win32.exe It will register this .exe into the System Registry to ensure it always starts on system bootup. See Payload for further details.
Attributes | Values |
---|---|
rdf:type | |
rdfs:label |
|
rdfs:comment |
|
dcterms:subject | |
dbkwik:malware/pro...iPageUsesTemplate | |
Platform |
|
Name |
|
Type |
|
pl |
|
Size |
|
abstract |
|