Virus Characteristics
This variant bears close similarities to
W32/Neroma.a@MM
.
Proactive detection:
Products running the 4.2.40 engine with the 4253 DATs or greater detect this threat as "virus or variant W32/Generic.a@MM" (with scanning of compressed files enabled).
This will be detected exactly as W32/Generic.a@MM with the 4292 DATs and higher.
Mail Characteristics
The virus is likely to be received in an email bearing the following characteristics:
Subject:
Time to 911!
Attachment:
original filename - likely NRS.EXE ("119.gif" label is used)
Body:
Hi, Nice butt!
For example:
When executed, the worm installs itself as:
%WinDir%\NRS.EXE
System startup is hooked via the following Registry key (NT/2k):
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\
CurrentVersion\Winlogon = Explorer.exe nrs.exe
Or via the SYSTEM.INI system file (9x):
[boot]
"shell" = Explorer.exe nrs.exe