W32.Smibag.Worm


Aliases: MSN-Worm.Sinmsn.c, W32/Smibag.worm.dr, Win32.HLLW.Admagic, W32/Smibag-A, Win32/HLLW.Smibag.C ,
Variants: WORM_SMIBAG.A, Worm/MSN.Sinmsn.DRP, W32/Simbag.A.worm, Win32/Smibag.B,

Classification: Malware
Category: Computer Worm

Status: Active & Spreading
Spreading: Moderate
Geographical info: Asia, North and South America, and some parts of Europe and Australia
Removal: Easy
Platform: W32
Discovered: 26 Sep 2003
Damage: Low

Characteristics: The W32.Smibag.Worm application is a worm that tries to multiply itself through the MSN messenger Korean version. It also executes and drops Adware.Admagic.

More details about W32.Smibag.Worm

The W32.Smibag.Worm program is a worm that tries to multiply itself through the MSN messenger Korean version. It also executes and drops Adware.Admagic. When the W32.Smibag.Worm program is opened, it inserts the following files: “.uz.exe”, “.ext.zip”, “.admagic.exe”, “.atl.dll”, “.msnVC.exe”, “.aw32x.dll”, “.sm.dll”, “C:admagic.exe”, “C:smb.exe”, “C: est.txt”, “%System%aw32x.dll”, “%System%sm.dll”, and “%System%uz.exe”. The worm adds value to the registry key. The worm utilizes the temporary file “MsnVC.exe” to spread itself through the MSN Messenger Korean Version.

The W32.Smibag.Worm program may download additional files for the computer without the user’s consent. The application may download additional files such as spyware application, Remote Access Tool, advertising software and backdoor Trojan program. The program may automatically install the downloaded files in the computer.