Sophos

W32/Navidad

Aliases
  • W32/Watchit
  • w32/navidad@m
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from January 2001 (3.41)
Detected by All Sophos products

Action

The Sophos Technical Support department has written a batch file which you can use to remove both W32/Navidad and W32/Navidad-B.
Run the batch file, reboot, then run it again.

More Information

W32/Navidad is an email worm. The worm arrives in an email message with an attachment called NAVIDAD.EXE.

If the attached program is launched, it displays a dialog box containing the text "UI".

UI

It then attempts to read new email messages and to send itself to the senders' addresses.

The worm copies itself into the Windows system directory with the filename WINSVRC.VXD and changes the registry so that it runs on Windows startup and before any file is run.

The worm also installs itself into the system tray.

Logo seen in system tray

If the user clicks on the icon, it displays a dialog box with the text "Nunca presionar este boton".

Nunca presionar este boton

If the user clicks the button, the worm displays a dialog box with the title "Feliz Navidad" and the text "Lamentablemente cayo en la tentacion y perdio su computadora".

Feliz Navidad

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer