I just got a new update for AVG6. 0 Update #276
Got this explanation of it from Grisoft/AVG:
DESCRIPTON:
I-Worm/Apost
------------
It is a new mass mailing worm written in Visual Basic.
The worm is spreading as a file README. EXE in messages with the
subject:
As per your request!
and the body:
Please find attached file for your review.
I look forward to hear from you again very soon.
Thank you.
When is the README. EXE file is executed it copies itself into Windows
directory and create in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
a value named "macrosoft"
pointing to the dropped copy of the worm.
Then the worm takes email addresses from Outlook address book
and starts sending itself.
Next, it displays a message box with a button 'Open'. When
you click on it, a fake error message appears:
WinZip SelfExtractor: Warning
CRC eror: 234#21
Update 276, that detects this worm, is ready on our web.
----------------------------------------------------------
If you have any comment, questions or need more information, please
feel free to contact us at -- email address removed --
Thank you for you interest in AVG Anti-Virus System.
--
GRISOFT Inc.
Developers of AVG Anti-Virus System
Got this explanation of it from Grisoft/AVG:
DESCRIPTON:
I-Worm/Apost
------------
It is a new mass mailing worm written in Visual Basic.
The worm is spreading as a file README. EXE in messages with the
subject:
As per your request!
and the body:
Please find attached file for your review.
I look forward to hear from you again very soon.
Thank you.
When is the README. EXE file is executed it copies itself into Windows
directory and create in the registry key:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
a value named "macrosoft"
pointing to the dropped copy of the worm.
Then the worm takes email addresses from Outlook address book
and starts sending itself.
Next, it displays a message box with a button 'Open'. When
you click on it, a fake error message appears:
WinZip SelfExtractor: Warning
CRC eror: 234#21
Update 276, that detects this worm, is ready on our web.
----------------------------------------------------------
If you have any comment, questions or need more information, please
feel free to contact us at -- email address removed --
Thank you for you interest in AVG Anti-Virus System.
--
GRISOFT Inc.
Developers of AVG Anti-Virus System
Last edited by a moderator: