MSIL.Cxover.A( Cxover.A, WORM_CXOVER.A )
SYMPTOMS: Presence under the windows directory of the virus executable with file names composed of a random number (between 0 and 2147483647) and the .exe extension, with the size of 61440 bytes.TECHNICAL DESCRIPTION: The virus spreads from desktop systems running Windows with .NET to mobile devices attached to the system, accessible trough RAPI (Remote API).When executed the virus checks if it is running on a Mobile / CE version of Windows (on a mobile device) or a desktop system. If it is running on a mobile device, then the virus will execute the following steps:
"the crossover virus - poc - by Dr. Julius Storm - The great walls of China that separated the domains between wired and wireless, desktop and handhelds have been reduce to ruble. Vxers are entering a new era of greater vx possibilities with the chance of reaching more systems around the world than ever before. The viruses of the past are nothing compared to what the future holds. 2006 marks the establishment of a New Cyberworld Order with vxers around the world united at the forefront. The time is now to prepare and defend, are you ready?" Removal instructions: Please let BitDefender delete your files.ANALYZED BY: Sándor LUKÁCS, BitDefender virus researcher |