The detection of a worm that steals Half-Life & Counter-Strike CD-Keys was announced on October 10th by Kaspersky Labs, an anti-virus and data security company based in Russia. The trojan containing worm, called Fleming, comes in a 53,248 byte sized program named BR2002.exe. Because infection can only be caused by running this program there is really nothing to worry about.
After the infected file has been executed Fleming springs to life using Microsoft Windows Messenger, a program which itself is a known affront to decency. Fleming sends the user's CD-Key to another messenger account, styggefolk@hotmail.com.[break="Learn more about how Fleming steals CD-Keys"]In order to infect more people Fleming sends a message to everyone in the user's contact list encouraging them to run the infected file. Fleming also tries to access other malicious programs on the web.
The Fleming program isn't a serious threat, the only reason it is noteworthy is because of the connection to Counter-Strike. None of the files used by the Fleming worm are currently able to be downloaded. This program is detected by Kaspersky AntiVirus, McAfee VirusScan, and Norton AntiVirus. Symantec calls it W32.HLLW.Henpeck and claims that it originated in Norway. For complete information and to see a copy of the message that Fleming sends out read Kaspersky Labs' announcement.
NOTE: MikeJ just pointed out to me that this was reported before in newsbits form. I didn't realize this because Symantec and Kaspersky having different names for it, my bad. And I know what you're thinking, but he's not related to DaveJ.
Semi-Related Fun Fact: Kaspersky Labs, the company that announced that Fleming steals Half-Life CD-Keys, has a long list of important clients including the Bureau of National Security of Poland, the Russian Federation President's Administration, the National Treasury of Kazakhstan, and the Ministry of Foreign Affairs of Italy.
After the infected file has been executed Fleming springs to life using Microsoft Windows Messenger, a program which itself is a known affront to decency. Fleming sends the user's CD-Key to another messenger account, styggefolk@hotmail.com.[break="Learn more about how Fleming steals CD-Keys"]In order to infect more people Fleming sends a message to everyone in the user's contact list encouraging them to run the infected file. Fleming also tries to access other malicious programs on the web.
The Fleming program isn't a serious threat, the only reason it is noteworthy is because of the connection to Counter-Strike. None of the files used by the Fleming worm are currently able to be downloaded. This program is detected by Kaspersky AntiVirus, McAfee VirusScan, and Norton AntiVirus. Symantec calls it W32.HLLW.Henpeck and claims that it originated in Norway. For complete information and to see a copy of the message that Fleming sends out read Kaspersky Labs' announcement.
NOTE: MikeJ just pointed out to me that this was reported before in newsbits form. I didn't realize this because Symantec and Kaspersky having different names for it, my bad. And I know what you're thinking, but he's not related to DaveJ.
Semi-Related Fun Fact: Kaspersky Labs, the company that announced that Fleming steals Half-Life CD-Keys, has a long list of important clients including the Bureau of National Security of Poland, the Russian Federation President's Administration, the National Treasury of Kazakhstan, and the Ministry of Foreign Affairs of Italy.
Comment