W32.Semisoft.59904

Risk Level 1: Very Low

Printer Friendly Page

Updated: February 13, 2007 11:51:21 AM
Also Known As: Net.666, Explore666
Type: Virus


This virus infects Windows .exe files, including 9x and NT. The virus creates infected files on the system and attempts to infect other Windows executables. The virus attempts to ping four different IP addresses believed to be located in New Zealand. It then opens a port, allowing remote-control access. The virus also attempts to modify the registry to execute the virus on startup. There are several variants of this virus, which have been found previously in the wild.

Protection

  • Initial Rapid Release version February 10, 1998
  • Latest Rapid Release version February 10, 1998
  • Initial Daily Certified version February 10, 1998
  • Latest Daily Certified version February 10, 1998
  • Initial Weekly Certified release date pending

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Difficult

Damage

  • Damage Level: Medium

Distribution

  • Distribution Level: Low

Writeup By: Eric Chien
Search by name
Example: W32.Beagle.AG@mm
Learn more about Zero-Day / Operation Aurora / Hydraq
Symantec DeepSight Screensaver