Summary

Summary
Action
More Information
| Included in our products from | February 2001 (3.42) |
|---|---|
| Detected by | All Sophos products |
Action

Summary
Action
More Information
The Sophos Technical Support department has written a batch file which you can use to remove both W32/Navidad-B and W32/Navidad.
Run the batch file, reboot, then run it again.
More Information
W32/Navidad-B is a variant of the W32/Navidad email-aware worm. The worm arrives in an email message with an attachment called EMANUEL.EXE.
If the attached program is launched, it displays a dialog box containing the text ";)".
It then attempts to read new email messages and to send itself to the senders' addresses.
The worm copies itself into the Windows system directory with the filename WINTASK.EXE and changes the registry so that it runs on Windows startup and before any file is run.
The worm also installs itself into the system tray.
If the user clicks on the icon, it displays a dialog box with the text "Nunca presionar este boton".
If the user clicks the button, the worm displays a dialog box with the title "Emmanuel....." and the text "Emmanuel-God is with us!May god bless u.And Ash, Lk and LJ!!".
If the user does not press the button but instead attempt to close the message the worm displays a message with the title "Emmanuel....." and the text "May GOd bless u;D";


