Content
W32/Erdine.worm
- Type
- Virus
- SubType
- Worm
- Discovery Date
- 12/17/2002
- Length
- 16,896 bytes
- Minimum DAT
- 4239 (12/23/2002)
- Updated DAT
- 4311 (12/24/2003)
- Minimum Engine
- 5.1.00
- Description Added
- 12/17/2002
- Description Modified
- 12/19/2002 2:18 PM (PT)
Tab Navigation
Characteristics
Update 12/19/2002:
Due to the late appearance of this virus and the extra quality assurance testing required, AVERT decided to include it in the next (4239) weekly DAT update. Unfortunately, this information did not make it into the readme.txt file. If you would like an extra.dat for this threat, please write to extradat@avertlabs.com
This worm copies itself to mapped, network, drives and adds an .SCR extension to local executable file names. When run, a message box is displayed:

- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run "OMOI" = C:\WINDOWS\kernel32.exe
Symptoms
- Presence of OMOI.SCR
- Presence of KERNEL32.EXE in the WINDOWS directory
- .EXE files renamed with the extension, .EXE.SCR
Method of Infection
This worm spreads by copying itself to mapped network drives.
Removal
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Characteristics
Characteristics -
Update 12/19/2002:
Due to the late appearance of this virus and the extra quality assurance testing required, AVERT decided to include it in the next (4239) weekly DAT update. Unfortunately, this information did not make it into the readme.txt file. If you would like an extra.dat for this threat, please write to extradat@avertlabs.com
This worm copies itself to mapped, network, drives and adds an .SCR extension to local executable file names. When run, a message box is displayed:

- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run "OMOI" = C:\WINDOWS\kernel32.exe
Symptoms
Symptoms -
- Presence of OMOI.SCR
- Presence of KERNEL32.EXE in the WINDOWS directory
- .EXE files renamed with the extension, .EXE.SCR
Method of Infection
Method of Infection -
This worm spreads by copying itself to mapped network drives.
Removal -
Removal -
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A