Win32.Fbound.C@mm( W32/Fbound.C )
SYMPTOMS: N/ATECHNICAL DESCRIPTION: It arrives in the following format:Subject: Attachment: Patch.exe After the user executes the attachment the worm searches for e-mail addresses in Outlook Express address book and send itself to those addresses in the same format it arrives. The worm uses the user SMTP settings for spreading itself. Win32.Fbound.A@mm is a slightly different version of this worm. It has the same subjects and attachment but the code was more structured. Removal instructions: The virus doesn\'t drop anything on the local machine. The only removal necessary is to delete the email message the virus arrived attached to.To delete the infected email message please follow these steps:
ANALYZED BY: Sorin Victor DudeaBitDefender Virus Researcher |