Hermes


Name: Hermes
Aliases: I-Worm.Hermes, W32/Hermes@MM, Troj_Hermes,
Ports:
Files: Seti@home 3.x to 4.0 upd.exe - Seti@home_twk.exe - Seti_patch.exe - Lunetic!.exe - Cih.exe - Energy.exe Ftip.exe Navidat.exe Click_me!.exe Cenik.exe Lunetic.scr Fucking.scr Micro$haft.scr Matrix.scr Reboot.scr Pamela.scr Techno.scr Funny!.scr Hermes.sc r School_in_da_flame.scr - 22,016 bytes (compressed with UPX) - 25,600 bytes (compressed with UPX) - 40,960 bytes (uncompressed) - 57,344 bytes (uncompressed)
Created:
Requires:
Actions: Worm / Mail trojan
The worm´s .exe file is distributed in a compressed format and is using one of twenty names randomly. Hermes contacts
Versions:
Registers: HKEY_LOCAL_MACHINE\Software\Microsoft\ Windows\CurrentVersion\
Notes: Works on Windows, together with MS Outlook.
Country: written in Czechoslovakia
Program: Written in Visual Basic.

© Copyright von Braun Consultants. This information may include technical inaccuracies or typographical errors. If you have any questions or further information about the actual trojan above, please contact Joakim von Braun at <joakim.von.braun@risab.se>