Aliases: Threat
Variants: N/A for W32.Chaim

Classification: Malware
Category: Computer Worm

Status: active
Spreading: Low
Geographical info: Low
Removal: Easy
Platform: W32
Discovered: 19 Sep 2006
Damage: Low

Characteristics: The W32.Chaim program is a worm that spreads by sending messages using AOL Instant Messenger.

More details about W32.Chaim

The W32.Chaim program software is known to arrive as an encrypted archive. It is commonly attached to an AOL IM message as a zipped archive. Users report that the message may appear to contain an enticing subject. The W32.Chaim program commonly uses polymorphic tactics. This means that the file name of its components often use different names. The malware program components are reported to use a mix of random characters and names of core system processes for its files. Registry changes may also be made to allow the software to run at system startup.

This software commonly connects to a remote server without the user’s knowledge. A configuration file containing the program’s settings may be downloaded from this server. The file often dictates files the program will download and their locations. These files may be spyware, adware or Trojan programs.