A new worm on the loos again a smart one,Who disables your antivirus software and spreading his self with out detection when avp is knocked down.
The use of mIRC makes the worm stand out from the crowd, Craig Coward, a spokesman for F-Secure, told Newsbytes, as well as its ability to disguise itself using random attachment and subject names. |
Like the Goner worm that spread earlier this month, Gokar is security software-aware and actively seeks to disable antivirus applications from most popular vendors.
The worm is detectable, the company adds, by the presence of a file called karen.exe in the main Windows directory.
Trend says that, if the infected machine is working as a Web server, the worm will modify the Microsoft IIS starting page to offer Web.exe as a downloadable file to all visits to the Web site.
Read the full article Here
Source: NewsBytes















