Skip to main content

New Internet Worm "Cervivec" Hits Users

22 March 2002

Kaspersky Labs, a leading international data-security software developer, reports the detection of the Internet-worm known as I-Worm.Cervivec. Cervivec is an Internet worm virus spreading via the Internet as an email attachment.

Kaspersky Lab, a leading international data-security software developer, reports the detection of the Internet-worm known as I-Worm.Cervivec. Cervivec is an Internet worm virus spreading via the Internet as an email attachment. The worm itself is a Windows PE EXE file about 230Kb in size, written in Delphi. It is compressed by UPX - the decompressed size is about 670Kb. The infected messages have Subject/Body content randomly selected from different variants in different languages:
Vtip
Cau posilam ti cerviky tak se na to podivej (virus to neni) Vtip
Cau posielam ti cerviky tak sa na to pozri (virus to neni) Witz
Hallo, Ich habe ein guter Witz-Wurm so sieh! (kein virus) blague
J'ai une bonne blague ca s'appelle verre de terre alors jette un coup d'oeil (il n'y a pas de virus) ���?
?��??�, ' ?-� ?��� ?��?R'�- � ����? ?�R?? �?�?�? (��R -? ?����) Joke
Hi, I have some cool joke - worms so have a look at it (no virus) Zart
Czesc, mam swietnz dowcip - robaka. Obejrzyj go sobie (to nie jest wirus) Chiste
Hola te mando los gusanilloes. Pues mirarlos (no es un virus)
The worm activates from infected email only if a user clicks on the attached file. The worm then installs itself into the system, runs its spreading and 'effect' routines (colored "worms" eating the desktop). While installing itself the worm copies itself to the Windows directory and to the \SYSTEM32 subdirectory with the name "ntkrnl.exe". It then registers that file in the system registry auto-run key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Kernel Loader = %WindowsDir%\system32\ntkrnl.exe -LOADDRIVERS=TRUE
The defense procedure against "Cervivec" has already been added to KasperskyT Anti-Virus database.

New Internet Worm "Cervivec" Hits Users

Kaspersky Labs, a leading international data-security software developer, reports the detection of the Internet-worm known as I-Worm.Cervivec. Cervivec is an Internet worm virus spreading via the Internet as an email attachment.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection, specialized security products and services, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help over 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

Related Articles Press Releases