Virus Information
Discovery Date: 02/10/2004
Origin: Unknown
Length: 18,432 bytes
Type: Virus
SubType: Worm

This threat is proactively detected as New Malware.b when scanning compressed files (default option) with program heuristics enabled.

This worm spreads by copying itself to the shared directory of various P2P clients and ICQ. It also tries to spread through email, though this was not observed to be successful in testing.

If the worm is not run from the Windows System directory or one of the default "shared" directories listed below, it will crash after creating a 0 byte Yeni.txt in the directory the file was run from. If the worm is run from one of these expected directories, it will create copies of itself using the following filenames:

DivX Pro.exe
Ftp Hacker.exe
GTA Keygen.exe
Half Life 2 Original KeyGen.exe
Hotmail Hacker.exe
ICQ Hacker.exe
Kaspersky Anti-Hacker.exe
Linux Kernel Hacker.exe
Matrix Screen Saver.exe
NetBIOS Hacker.exe
New Exploit.exe
New Keylogger.exe
SYSTEM\NewVirusCleaner.exe
PopStar-Abidin.mp3.exe
PopStar-Bayhan.mp3.exe
PopStar-Firdevs.mp3.exe
These copies will be created in the following default "shared" folders for various applications:

MORE: http://vil.nai.com/vil/content/v_101005.htm