W32/Wecorl is a virus which spread automatically by using a vulnerability in Server Service. This virus is build to quietly download and execute poisonous contents from the remote server.
When the executable programe run on the infected system, the virus copies itself to the following location.
%Temp%\Install.2008.dat
W32/Wecorl deletes %WINDIR%\system32\dllcache\svchost.exe files from the system and change them to svchost.exe
Effects of W32/Wecorl.a are the presencee of the registry key and outgoing HTTP traffic to the domains.
Latest DATs and the Engine combination will be able to find out and remove this threat.




No comments yet... Be the first to leave a reply!