Encyclopedia

Nugache.M

 
Threat LevelHigh threatDamageSevereDistributionNot widespread
Common name:Nugache.M
Technical name:W32/Nugache.M.worm
Threat level:Medium
Type:Worm
Effects:  

It logs the keystrokes typed by the user, receives instructions via an IRC server and disables the Windows XP firewall. It spreads via email and instant messaging programs.

Affected platforms:

Windows 2003/XP/2000/NT/ME/98

First detected on:Aug. 20, 2007
Detection updated on:Aug. 20, 2007
StatisticsNo
Yes, using TruPrevent Technologies

Brief Description 

    

Nugache.M is a worm that logs the keystrokes typed by the user. This way, it could obtain confidential information about the user, such as passwords.

Additionally, it disables the Windows XP firewall and it connects to an IRC server in order to receive instructions, such as launching denial of service (DoS) attacks or connecting to an FTP server.

Nugache.M spreads via email and instant messaging programs, such as AOL Instant Messenger (AIM) and MSN Messenger.

Visible Symptoms 

    

Nugache.M is difficult to recognize, as it does not display any messages or warnings that indicate it has reached the computer.

However, it is easy to recognize when it spreads via email, as it reaches the computer in a message with the following characteristics:

  • Subject: one of the following:
    k, here
    hey!
    hey
    FW:
    okay
    here
    hi
    hey there
    light
    what up
    lol
    heh
    sup
  • Attached file: one of the following:
    SELF NUDE.SCR
    MY PIC.SCR
    DSC1060193.SCR

Last updated:  20/08/2007 

Virus News

3/10/09.-More than 10 Million Worldwide Were Actively Exposed to Identity Theft in 2008

3/5/09.-Cyber-crooks manipulate Internet searches to sell fake antivirus products

3/2/09.-VideoPlay adware infections grew 400% in February through malicious use of Web 2.0 pages

[+ Noticias]