W32/Snapper-A

Category: Viruses and Spyware
Type: Win32 worm
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Snapper-A spreads through the emails using a known IE vulnerability.

For more details see MS03-040.

When an infected message is opened the link to the malicious site is activated and a script component with the filename htmlhelp.cgi is executed.

When run htmlhelp.cgi extracts and the main component of the worm to the Windows system folder as IELOAD.DLL and launches it.

W32/Snapper-A sends infected messages to all entries in the Outlook address book.

download Try Sophos products for free
Download now