Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

W32/Bereb.worm!p2p

Mar 24, 2004 12:40AM PST

Virus Information
Discovery Date: 11/23/2004
Origin: Unknown
Length: 200Kb Approx.
Type: Virus
SubType: P2P Worm
Description Added: 03/24/2004
Description Modified: 03/24/2004 7:48 AM (PT)

When run, it copies itself into the %Windir% folder as taskmgr.com and creates the following registry run keys to load itself at system startup:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "taskmgr" = %Windir%\taskmgr.com

HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "WinMX" = C:\Program~1\WinMX\WinMX.exe -m

It also drops Library.dat (contains encrypted data) into folder C:\Program Files\WinMX.

More: http://vil.nai.com/vil/content/v_101130.htm

Discussion is locked