W32.Banwarum@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer. The worm also spreads through the network by exploiting the Microsoft Windows ASN.1 Library Bit String Processing Variant Heap Corruption Vulnerability (as described in Microsoft Security Bulletin MS04-007). The worm also opens a back door via HTTP access.
This new email threat should be easy for most users to avoid. The text of the message is in German and this new worm exploits vulnerabilities in MS04-007. Users should be cautious with all email messages.
Banwarum Worm - Offers Tickets for the WORLD CUP?
Diagram of worm behavior