W32.Collo


Aliases: W32/Collo-A, Worm/Collo.A, WORM_COLLO.A, Win32.Collo.A, Collo.A Worm
Variants: N/A

Classification: Malware
Category: Computer Worm

Status: active
Spreading: Low
Geographical info: Low
Removal: Easy
Platform: W32
Discovered: 04 Feb 2002
Damage: low

Characteristics: Win32.Worm.Collo is a mass mailing worm. It is known that it automatically multiplies itself inside your computer system without the user’s involvement.

More details about W32.Collo

Independently worms are known as programs that are able to propagate independently in the computer. As such, it maybe harmful to the computer as it may affect systems files and folder and would even steal some of your confidential data. This worm is also known as Worm.Win32.Collo.a W32/Cool.worm.gen, W32, Win32.HLLM.Cool.49152, Troj/Coole-A, Win32/Collo.worm , WORM_COLLO.A, Worm/Collo.A, Win32:Cool-B, Worm/Collo, Win32.Collo.A@mm, Worm.Collo.A, Worm Generic and Win32/Collo.A. This worm poses great threat and may represent security risk for the compromised system and/or its network environment. It continually replicates itself across its newly find network. This is sometimes also called as Network-aware worm. Its propagation techniques usually starts with manual installation which means that someone has been opening or clicking files or emails infected with this virus. It can also be installed through fully automatic propagation, through which the worm uses security leaks of the Operating System. This means no user has been opening or clicking any files, file attachments and or programs that come within your email services. Root causes of this worm usually come from an exploit of vulnerable software. Mostly, these are always detected by Microsoft antivirus engine.

This worm automatically sends itself to Windows addresses. It will then send this message with subjects like, “Check out this cool program,” or “Wow dieses Coole Programm.” You may also see attachments like Cool Program.exe and or Cool Programma.exe. In its text body, you may see these messages, “I'm writing you this e-mail because I just found out about a very cool program that you need to see. Go check it out yourself, you will love it. Bye bye, your old Friend Energy,” and or " Ich schreib Dir diese e-mail, weil ich dieses Ober Coole Programm gefunden habe. Schau es Dir am besten selbst mal an, Du wirst es Lieben. Tschau, Dein alter Kumpel Energy”. If an infected email is opened, the worm will open task processes and/or programs such as Progman.exe Regedit.exe, Cdplayer.exe, Sndrec32.exe, Pbrush.exe, Write.exe, Scandskw.exe, Calc.exe, Explorer.exe and Notepad.exe.