Kelvir.B (Kelvir.A at Symantec) is an MSN Messenger worm that appeared yesterday, has now been characterized by Symantec as spreading in the field. The worm arrives as a link to the file cute.pif on a web site on the home.att.net domain. It also downloads a variant of W32/SDBot, a backdoor and open share worm, as patch.exe from a web site on the home.comcast.net domain.
Details
Kelvir.B was discovered on March 6, 2005, with details first published shortly after midnight GMT. So far, details are limited, other than that at this time it appears that the targeted web sites are still up (I am unable to verify this as no description that includes the URL uncensored has yet been published).
So far it is unknown how quickly Kelvir.B is spreading, but Symantec's characterization of the worm as Medium on their Wild scale and their publishing of a temporary description while they were investigating the threat suggests that it may be spreading somewhat quickly in the MSN Messenger community.
The format for messages is “omg this is funny! (Link to worm)“.
Protection
Updated detections for most antivirus programs should appear within the next 24 hours or so. It is unlikely emergency detection will be published, as the worm reminds a Low risk threat on all descriptions at this time. In the meantime, MSN Messenger users should exercise common sense and not open any executable file format that is sent to them randomly, including .pif, which this worm uses.
Infected users should wait for detection files and/or more detailed information and removal information to be published before attempting to remove the worm. Until then, infected users should avoid connecting to the Internet or any open network.
Links
Secunia - Compiles latest descriptions and links.
Sophos - Basic description with some details. No removal instructions. “More detailed information to follow shortly.“
McAfee - Basic description with some details. No removal instructions.
Symantec - Very basic description with no details. No removal instructions. “More information [will be posted] as it becomes available.” Refers to worm as “Kelvir.A.”
Posted
Mar 06 2005, 05:49 PM
by
trafton