FRISK Software International


Summary of Rodok
Alias:Henpeck, Br2002
Discovered: 9 Oct 2002
Infection Method:Link to a .EXE file sent via MSN Messenger
 
Jump to:
Brief description

Brief Description
A new Messenger worm has been found on October 9th, 2002. The worm uses the following message:

 "Hey!! Could you please check out this program for me ? : )
 I made it myself and want people to test it.
 Its a readme with the program that explains what it does!
With this text the worm tries to convince the user to click on a link and download the file from a page on http://home.no.net

It also contains the following explanation to the link to Br2002.exe:

 There you can download it! give me advices on what to upgrade please!!
The ISP responsible for the web site has closed the webpage in question. This makes the worm unable to spread further.


[Analysis: Katrin Tocheva, F-Secure Corp.; October 9th, 2002]
 


Stay up to date with important developments via e-mail.
Stay up to date with life cycle policies for F-PROT Antivirus for Windows.
Virus news and information directly to your desktop.
Definitions of common antivirus terminology.
For further virus information, please try our partners' websites:

Authentium

perComp Verlag
(in German)
 

agoat@klaki.net argentina@f-prot.com argentina@frisk.is argentina@complex.is argentina@f-prot.is argentina@frisk-software.com argentina@f-prot.net argentina@f-prot.co.uk brazil@f-prot.com brazil@frisk.is brazil@complex.is brazil@f-prot.is brazil@frisk-software.com brazil@f-prot.net brazil@f-prot.co.uk malta@f-prot.com malta@frisk.is malta@complex.is malta@f-prot.is malta@frisk-software.com malta@f-prot.net malta@f-prot.co.uk a.bjani@f-prot.com a.bjani@frisk.is a.bjani@complex.is a.bjani@f-prot.is a.bjani@f-prot.co.uk a.bjani@frisk-software.com a.bjani@f-prot.net z.fifl@f-prot.com z.fifl@frisk.is z.fifl@complex.is z.fifl@f-prot.is z.fifl@f-prot.co.uk z.fifl@frisk-software.com z.fifl@f-prot.net strumpuri@complex.is strumpure@complex.is strumpuru@complex.is