W32/Hagbard-A copies itself to a number of locations on the hard drive, including shared folders for various peer-to-peer applications. The worm also installs a web server, allowing a remote user access to files on the infected system. The installed file is also detected as W32/Hagbard-A.
W32/Hagbard-A may send messages to other users of Windows Messenger, containing a link and the following text:
please download this...its only small brb
The link points to a copy of the worm stored on the infected system.
The worm may change the Start Page in Internet Explorer.
More information can be found at this Sophos page.
Loading Comments...