Quote
This is a worm written in VB with the following characteristics:
1. The worm attempts to lure victims to follow a URL link, in so doing downloading a copy of it, and infecting themselves. It monitors Internet Explorer windows in order to detect when a new message is being created within MSN Hotmail.
2. The worm monitors browser window to detect when MSN hotmail is being used for sending new mail, and inserts text to such messages, which contains a URL from where the worm is downloaded if the recipient clicks on the link.
3. It deletes files on the root of C: and A:, and copies itself there in place of those files, appending a .EXE file extension
1. The worm attempts to lure victims to follow a URL link, in so doing downloading a copy of it, and infecting themselves. It monitors Internet Explorer windows in order to detect when a new message is being created within MSN Hotmail.
2. The worm monitors browser window to detect when MSN hotmail is being used for sending new mail, and inserts text to such messages, which contains a URL from where the worm is downloaded if the recipient clicks on the link.
3. It deletes files on the root of C: and A:, and copies itself there in place of those files, appending a .EXE file extension
Hotmatom Worm - New MSN Hotmail based worm deletes files
http://secunia.com/virus_information/27456/hotmatom/
http://vil.nai.com/vil/content/v_138829.htm
http://www.sarc.com/avcenter/venc/data/w32.hotmatom.html

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.



Back to top








