Content
W32/Gemel.worm
- Type
- Virus
- SubType
- Internet Worm
- Discovery Date
- 01/29/2003
- Length
- 35,328
- Minimum DAT
- 4246 (02/05/2003)
- Updated DAT
- 4246 (02/05/2003)
- Minimum Engine
- 5.1.00
- Description Added
- 01/29/2003
- Description Modified
- 01/31/2003 10:27 AM (PT)
Tab Navigation
Characteristics
This worm can spread via floppy disk, file sharing on KaZaa, and ICQ.
When run, the worm deletes the following system files:
- regedit.exe
- msconfig.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run "GEDZAC" = "C:\Windows\Guindows\GEDZAC.EXE"
The worm copies itself to c:\WINDOWS\Guindows\GEDZAC.EXE. It also creates lots of copies in the following folders, if the folders exist on the machine.
- c:\Program Files\Grokster\My Grokster
- c:\ARCHIV~1\Grokster\My Grokster\
- c:\Program Files\Morpheus\My Shared Folder\
- c:\archiv~1\Morpheus\My Shared Folder\
- c:\Program Files\ICQ\shared files
- c:\archiv~1\ICQ\shared files\
- c:\Program Files\KaZaA\My Shared Folder\
- c:\ARCHIV~1\KaZaA\My Shared Folder\
Symptoms
Method of Infection
This worm spreads via floppy diskette, KaZaa, and ICQ.
Removal
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Aliases
- W32/P2P.Torres.Worm (CA)
- Worm.P2P.Gemel.a (AVP)
- WORM_GEMEL.A (Trend)
Characteristics
Characteristics -
This worm can spread via floppy disk, file sharing on KaZaa, and ICQ.
When run, the worm deletes the following system files:
- regedit.exe
- msconfig.exe
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run "GEDZAC" = "C:\Windows\Guindows\GEDZAC.EXE"
The worm copies itself to c:\WINDOWS\Guindows\GEDZAC.EXE. It also creates lots of copies in the following folders, if the folders exist on the machine.
- c:\Program Files\Grokster\My Grokster
- c:\ARCHIV~1\Grokster\My Grokster\
- c:\Program Files\Morpheus\My Shared Folder\
- c:\archiv~1\Morpheus\My Shared Folder\
- c:\Program Files\ICQ\shared files
- c:\archiv~1\ICQ\shared files\
- c:\Program Files\KaZaA\My Shared Folder\
- c:\ARCHIV~1\KaZaA\My Shared Folder\
Symptoms
Symptoms -
Method of Infection
Method of Infection -
This worm spreads via floppy diskette, KaZaa, and ICQ.
Removal -
Removal -
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A