Quote
This is a worm written in VB with the following characteristics:
1. The worm attempts to lure victims to follow a URL link, in so doing downloading a copy of it, and infecting themselves. It monitors Internet Explorer windows in order to detect when a new message is being created within MSN Hotmail.
2. The worm monitors browser window to detect when MSN hotmail is being used for sending new mail, and inserts text to such messages, which contains a URL from where the worm is downloaded if the recipient clicks on the link.
3. It deletes files on the root of C: and A:, and copies itself there in place of those files, appending a .EXE file extension
1. The worm attempts to lure victims to follow a URL link, in so doing downloading a copy of it, and infecting themselves. It monitors Internet Explorer windows in order to detect when a new message is being created within MSN Hotmail.
2. The worm monitors browser window to detect when MSN hotmail is being used for sending new mail, and inserts text to such messages, which contains a URL from where the worm is downloaded if the recipient clicks on the link.
3. It deletes files on the root of C: and A:, and copies itself there in place of those files, appending a .EXE file extension
Hotmatom Worm - New MSN Hotmail based worm deletes files
http://secunia.com/virus_information/27456/hotmatom/
http://vil.nai.com/vil/content/v_138829.htm
http://www.sarc.com/avcenter/venc/data/w32.hotmatom.html

Help



Back to top








