Sophos

W32/NewApt

Aliases
  • W32.NewApt.Worm
  • Worm.NewApt
  • I-Worm.NewApt
Category
Type
What to do
Prevalence low high

Summary

 
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/NewApt is an email-aware worm that forwards itself as an attached executable file in an email message to addresses in your address book.

If your email program does not support HTML the message text reads:

he, your lame client cant read HTML, haha. click attachment to see some stunningly HOT stuff

If your email program supports HTML the text includes reference to a website and includes the message:

http://stuart.messagemates.com/index.html Hypercool Happy Year 2000 funny programs and animations?. We attached our recent animation from this site in our mail ! Check it out!

Sophos would like to point out that the MessageMates company have no connection with this virus. The virus pretends to be connected to MessageMates in an attempt to encourage people to run the executable file.

When launched the executable file displays a message box including the text:

The dinamic link library giface.dll could not be found in specified path

The attached executable file can have any of the following filenames:

baby.exe
bboy.exe
boss.exe
casper.exe
chestburst.exe
cooler1.exe
cooler3.exe
copier.exe
cupid2.exe
farter.exe
fborfw.exe
gadget.exe
goal.exe
goal1.exe
g-zilla.exe
hog.exe
irnglant.exe
monica.exe
panther.exe
party.exe
pirate.exe
saddam.exe
theobbq.exe
video.exe

W32/NewApt alters the Windows Registry so that the worm is reloaded each time Windows is restarted.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer