Welcome to the Virus Encyclopedia of Panda Security.
Energy.A does not have any destructive effects. Its main aim is to spread and infect other computers.
Energy.A creates the following files:
- ENERGY.EXE, in the Windows system directory. This file is a copy of the worm.
- SETUP.EXE. This file is a copy of the file that carries out the infection (ENERGY.EXE). There is also a compressed copy of this file with a RAR extension.
Once it has infected a computer, Energy.A captures all the processes of the MAPI libraries (used to manage email) and intercepts the function MAPISendMail, which the worm uses to spread in messages containing RAR files.
Additionally, Energy.A is run as an operating system service, therefore, it will not be visible to the user, as it does not appear in the list of processes of the Windows Task Manager.
Means of transmission
Energy.A spreads via email. When it detects the function MAPISendMail, Energy.A checks if the message being sent contains a compressed file with a RAR extension. If so, the worm opens the file and copies its code to it under the name SETUP.EXE.
Energy.A is 10,752 bytes in size.
This worm includes the text below in its code:
[I-Worm.Energy] by Benny/29A