Aliases: Werly.A, W32/Werly.A, Win32.Werly.A, Virus.Win32/Werly.A, Virus.W32.Werly.A
Variants: Win32.Werly.A, Virus.Win32.Werly.A, Virus.W32/Werly.A

Classification: Malware
Category: Computer Virus

Status: Active & Spreading
Spreading: Slow
Geographical info: Asia, North and South America, and some parts of Europe and Australia
Removal: Easy
Platform: W32
Discovered: 26 Sep 2008
Damage: Low

Characteristics: The W32/Werly.A program is a virus that infects PE files and spreads via local and mapped network drives. It affect windows platforms such as Windows 2000, Windows 98, Windows 95, Windows Me, Windows Server 2003, Windows NT, and Windows XP.

Once Win32.Werly.A program is executed on your system, it separates its file content into 2 parts and generates these files. This files are named bv.map and INSTALL.Exe from the windows directory. The file bv.map has pure virus body while the INSTALL.EXe file is the old clean victim. The virus will then scan all .exe files in your compromised computer, and infects it by pre-pending the bv.map (virus body) to the beginning of.exe files.. Once the compromised computer is fully executed by this virus, there become the existence of the dropped file and executable files are in increased in size. W32/Werly.A is a virus that spreads through mapped and local network drives.

W32.Werly.A is a worm infection that could disguise as a registry file and utilize Windows exploits to download and install dangerous programs into the infected computer. Once executed, W32.Werly.A activates infected rcxe.tmp, bv.exe, bv.tmp, bv.map, files on the Windows folders to hide from firewall programs. W32.Werly.A is usually spread via pornographic websites, corrupt freeware/shareware and file sharing downloads or via media codec updates and infected ActiveX. W32.Werly.A is a destructive worm and hacker program that could steal secret data, and may harm your system files!