Need help? Ask the community or hire an expert.
Go to Avira Answers
Alias:
Type:Worm 
Size:23,320 Bytes 
Origin: 
Date:00-00-0000 
Damage:Sent by email 
VDF Version:6.23.00.00 
Danger:Low 
Distribution:High 

DistributionThe email sent by the worm:

Subject: Enjoy this friendship-joke Screen Saver!!!!
Fw: Enjoy this friendship-joke Screen Saver!!!!
Have a nice day!!!!

Attachment: Friends.scr

Technical DetailsWhen activated, Worm/Lentin.2 copies the Address Book into C:\%WinDIR%\%variable%.dll, where the varaible file name has 5 random letters. For example: ABCDEABCDE.dll or CEGIKCEGIK.dll.
It changes the registry entry:
HKEY_LOCAL_MACHINE\Software\Classes\exefile\shell\open\command c:\recycled\%variable%" %1 %*"
The worm will be reactivated every time a file is opened.

Then, it tries to set one of the following pages as Internet Explorer homepage:
www.achayans.com
www.sunnt.com/suryatv
www.malayalamchannel.com
www.india.com
www.kerala.com
www.asianetglobal.com
www.malayalamanorama.com
Description inserted by Crony Walker on Tuesday, June 15, 2004

Back . . . .