|
|
|
VIRUS NAME
: W32/Quin.worm
Virus
Characteristics
This threat
is detected as New Worm with the 4120-4220 DATs when scanning with program heuristics
enabled.
This worm spreads via Internet Relay Chat using the mIRC client and the DCC
SEND command. When run, the worm copies itself to the file %WINDIR%positron.exe
(ie. C:\WINDOWSpositron.exe). It retrieves the default mIRC installation path
from the following registry key:
It uses this information
to overwrite (or create if not present) the SCRIPT.INI file with instructions
to send itself to users who join the same IRC channel as the infected user.
Finally, an error box is also displayed which reads "QTINTF3.DLL Not Found!".
Symptoms
Presence of a message box which reads "QTINTF3.DLL Not Found!".
Method
Of Infection
This worm consists of an executable that, when run on a system with the mIRC
client installed, configures the mIRC program to send itself to other IRC users.
|
|
|