W32.Refoav@mm
Aliases: W32.Refoav@mm, Worm.W32/Refoav@MM, W32/Refoav, Refoav
Variants: N/A
Classification: Malware
Category: Computer Worm
Status: Active & Spreading
Spreading: Slow
Geographical info: North America
Removal: Easy
Platform: W32
Discovered: 07 Apr 2003
Damage: Low
Characteristics: W32.Refoav@mm is a mass-mailing worm. It infects Windows systems. It uses Microsoft Outlook to send itself to all the contacts in the Outlook Address Book. It is a slow infector. It causes low damage on an infected computer. The threat can be removed easily using an updated antivirus program.
W32.Refoav@mm Removal Tool
If you have Malware on your computer it will cause annoyances and will damage your system. You should either:
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
RECOMMENDED:
We recommend that you scan your system for malware. Our partner has a computer worm removal tool to automatically clean W32.Refoav@mm from your computer.
More details about W32.Refoav@mm
W32.Refoav@mm is a worm written in the Microsoft Visual Basic programming language. It is a mass-mailing worm. The subject of the email it sends reads: No esta registrado el usuario. The email has an attachment file named FOAVRE.exe. When W32.Refoav@mm runs, it copies itself as C:\FOAVRE.exe. The attributes of the file are set to Hidden and Archive. It also creates the files: Vbseli.vbs and Datospc.dat in Drive C. These files are set to Hidden and Archive. Teh worm also modifies the registry to make sure that it runs every time that Windows is started. It uses Microsoft Outlook to send itself to all the contacts in the Outlook Address Books. When the file vbseli.vbs runs, it displays five messages. It also removes the value that the worm adds in the registry and deletes the files: FOAVRE.exe and Vbseli.vbs.The W32.Refoav@mm program places a copy of itself in the system. This is commonly an executable file placed in the System or Windows folder. The file name used may be similar to those of legitimate processes. This is to prevent detection and removal. The process is also added to the system registry. This makes sure the application runs once the system starts. The W32.Refoav@mm application connects to a remote server. This server is commonly hard-coded in the program. It may be specified using a web or IP address. The backdoor software then waits for commands to execute in the infected system.
Browse for more malware information
- W32.Refoav@mm
- W32.Reidana.A
- W32.Relfeer
- W32.Relnek.A
- W32.Remabl.Worm
- W32.Remadmin
- W32.Remadworm
- W32.Renama.A@mm
- W32.Renco@mm
- W32.Repad.Worm
- W32.Reploret
- W32.Resdoc
- W32.Resik.A
- W32.Rexli.A@mm
- W32.Reztrict@mm
- W32.Ridnu.B
- W32.Rinbot!gen
- W32.Rispif.A
- W32.Rokid
- W32.Ronoper.B@mm
- W32.Rontokbro
- W32.Rontokbro.AN@mm
- W32.Row@mm
- W32.Ruland.A@mm
- W32.Rungbu
- W32.Rusty@m
- W32.SQLExp.Worm
- W32.Sachiel
- W32.Sachy.A
- W32.Safook