VIRUS
NAME : W32/MyLife.f@MM
Internet
Worm Characteristics
This mass-mailing worm is very similar to a previous variant detected
as W32/MyLife.c@MM.
It uses Microsoft Outlook to send itself to all addresses in the Outlook
Address book and addresses on the MSN Messenger contact list. It arrives
in an email containing the following information:
Subject: the list
Attachment: List480.TXT.scr
A dropped copy of
the worm is executed at system startup thanks to the following Registry
key:
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion_
\Run "sys" = C:\WINDOWS\SYSTEM\List480.TXT.scr
Symptoms
Presence of the file List480.TXT.scr (7,680 bytes) in the Windows System
directory.
Method
Of Infection
When executed, the worm propagates itself to all addresses found in the
Outlook Address book and addresses on the MSN Messenger contact list,
using Microsoft Outlook. The worm copies itself to the System folder,
modifying the Registry to run this copy at subsequent startup.
|