W32.Savix
Aliases: N/A
Variants: N/A
Classification: Malware
Category: Computer Worm
Status: Active & Spreading
Spreading: Slow
Geographical info: Asia, North and South America, and some parts of Europe and Australia
Removal: Easy
Platform: W32
Discovered: 18 Sep 2008
Damage: Low
Characteristics: The W32.Savix program is a worm that propagates through removable media and fixed drives.
W32.Savix Removal Tool
If you have Malware on your computer it will cause annoyances and will damage your system. You should either:
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
RECOMMENDED:
We recommend that you scan your system for malware. Our partner has a computer worm removal tool to automatically clean W32.Savix from your computer.
More details about W32.Savix
The W32.Savix is a worm that propagates through removable media and fixed drives. Once the worm is opened, the worm propagates by duplicating itself to the source of all drives from C to I as “%DriveLetter%:\.x”. The W32.Savix worm also makes the file “%DriveLetter%:\autorun.inf” in the source of all drives from C to I so that it opens when the drives are opened. The worm also makes and changes registry keys so that it opens each time the Windows starts. The worm shows the following message w/ a math question and then tries to reboot the computer system after 20 seconds: “Wilcome Let Play a Game better than Silk[REMOVED]it.”, “125 * 45 - 50/2 = Here ?”, “else i don't need to Tell you what”, and “will Happened”.The W32.Savix worm software adds its executable files to the system registry. This allows it to run at system startup. The DLL (Dynamic Link Library) modules are registered as Browser Helper Objects (BHO programs). This gives the malware program access to the web browser’s resources. Security software will consider the program part of a legitimate application. This program opens an unused port to create a backdoor. This is used to connect to a remote server without the user’s consent. Files will be downloaded and saved in the infected computer. These are commonly installers for other unwanted programs.
Browse for more malware information
- W32.Savix
- W32.Scane
- W32.Scard
- W32.Schting.A
- W32.Scrapkut
- W32.Scrimge!gen
- W32.Sdbot.DJG
- W32.Secefa.A
- W32.Secet.Worm
- W32.Sejese
- W32.Selotima.A
- W32.Serab@mm
- W32.Serflog.A
- W32.Serot@mm
- W32.Setclo
- W32.Shakir
- W32.Shangxing.A
- W32.Shatrix@mm
- W32.Shelp
- W32.Shermnar.B.Worm
- W32.Shiba.Worm
- W32.Shoes@mm
- W32.Shoho@mm
- W32.Shufa@mm
- W32.Sibaru.A
- W32.Sigougou
- W32.Silly!gen
- W32.SillyDC
- W32.SillyFDC
- W32.SillyIM