Sophos

W32/Navidad-B

Category
Type
What to do
Prevalence low high

Summary

 
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for disinfecting PE executables.

The Sophos Technical Support department has written a batch file which you can use to remove both W32/Navidad-B and W32/Navidad.
Run the batch file, reboot, then run it again.

More Information

W32/Navidad-B is a variant of the W32/Navidad email-aware worm. The worm arrives in an email message with an attachment called EMANUEL.EXE.

If the attached program is launched, it displays a dialog box containing the text ";)".

;)

It then attempts to read new email messages and to send itself to the senders' addresses.

The worm copies itself into the Windows system directory with the filename WINTASK.EXE and changes the registry so that it runs on Windows startup and before any file is run.

The worm also installs itself into the system tray.

Logo seen in system tray

If the user clicks on the icon, it displays a dialog box with the text "Nunca presionar este boton".

Nunca presionar este boton

If the user clicks the button, the worm displays a dialog box with the title "Emmanuel....." and the text "Emmanuel-God is with us!May god bless u.And Ash, Lk and LJ!!".

Emmanuel-God is with us!May god bless u.And Ash, Lk and LJ!!

If the user does not press the button but instead attempt to close the message the worm displays a message with the title "Emmanuel....." and the text "May GOd bless u;D";

May GOd bless u;D

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer