Protector
Plus
Anti virus software for
Windows
(XP, 2000, 2003, NT, Me, 98, 95)
Exchange
NetWare
 |
W32/Sumom.A Worm
Information about the W32/Sumom.A Worm:
W32/Sumom.A is a worm. The worm will infect Windows systems. The worm spreads through MSN Messenger and shared network drives.
The worm arrives as an infected attachment through MSN Messenger. The attachment will be any one of the following;
See my lesbian friends.pif
Jennifer Lopez.scr
My new photo!.pif
Me on holiday!.pif
The Cat And The Fan piccy.pif
How a Blonde Eats a Banana...pif
Mona Lisa Wants Her Smile Back.pif
Topless in Mini Skirt! lol.pif
Fat Elvis! lol.pif
Crazy frog gets killed by train!.pif
Annoying crazy frog getting killed.pif
Upon execution of the infected attachment, the worm copies itself as;
My new photo!.pif
See my lesbian friends.pif
Mona Lisa Wants Her Smile Back.pif
Jennifer Lopez.scr
How a Blonde Eats a Banana...pif
Annoying crazy frog getting killed.pif
Crazy frog gets killed by train!.pif
Fat Elvis! lol.pif
LOL that ur pic!.pif
lspt.exe
Me on holiday!.pif
The Cat And The Fan piccy.pif
Topless in Mini Skirt! lol.pif
In the root of Windows installed folder.
It also copies itself as FORMATSYS.EXE, SERBW.EXE in the Windows system folder and MSMBW.EXE in the Windows folder.
It also drops the following files in the root of Windows installed folder.
Message to n00b LARISSA.txt
Crazy-Frog.Html
British National Party.jpg
The worm modifies registry at the following location to load itself during each startup.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
The worm also attempts copies itself as Messenger Plus! 3.50.exe, MSN all version polygamy.exe and MSN nudge bomb.exe to the following shared folders.
My Shared Folder
Shared
eMule
It also copies AUTORUN.INF and AUTORUN.EXE to all the CD ROMs written in
the infected system.
The worm tries to terminate some of the security related processes. It also blocks access to some of the security related websites.
This worm first appeared on 7th March, 2005.
Other
names of W32/Sumom.A Worm:
This Worm is also known as WORM_FATSO.A, Fatso.A, W32.Serflog.A, IM-Worm.Win32.Sumom.a, W32/Sumom-A..
Click here to download a
30 day Evaluation Copy of
Protector Plus anti virus for your operating system
|