to je klasican spy worm. aliases:I-Worm.Fearso, Win32/Farex.A, PE_NOFEAR.A, W32/Nofer.A@mm, W95/Fearso.A@mm
Description
W32/Nofer-A is an internet worm that will attempt to email itself to addresses
found from a variety of sources on the local machine. W32/Nofer-A will also try to infect executable files.
W32/Nofer-A will copy itself to svchost.exe and to a randomly named executable file in the Windows folder. It creates a registry entry in
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
that points to the randomly named executable file to ensure the worm is run at system startup.
W32/Nofer-A will also attempt to spread using peer-to-peer networks
kolko sam procitao najlakse se odstranjuje sa ovim AVom
http://downloads.sophos.com/pe...3g7Uey4I76GbgZD0yMjQ=/angz.exe