Need help? Ask the community or hire an expert.
Go to Avira Answers
Size:24.576 Bytes 
Damage:Sent by email. 
VDF Version: 

DistributionIt sends itself by email using Microsoft Outlook. The email sent by the worm has the following structure:
Subject: As per your request!
Body: Please find attached file for your review I lokk forward to hear form your again very soon. Thank you.
Attachment: README.EXE

Technical DetailsW32/Apost is an Internet worm, programmed in Visual Basic 6. If the worm is activated, a window appears indicating a false WinZip error message. When the user clicks on "Aceptar" button, the worm sends itself by email, using Microsoft Outlook Address Book. After sending emails, another window appears.
The worm creates copies of itself in Windows directory and in root directories of the local drives (C:\; D:\; ...) as README.EXE, which has the standard Visual Basic 6 application icon.
The worm makes the following registry entry:
HKCU\Software\Microsoft\Windows\Current Version\Run\macrosoft = %Windows%\Readme.exe
Description inserted by Crony Walker on Tuesday, June 15, 2004

Back . . . .