Aanmelden
Welkom,
Language:
Nederlands
English
Deutsch
Français
Español
Italiano
Nederlands
Português
Türkçe
Русский
日本語
简体中文
繁體中文
한국어
Meer informatie over ons bedrijf en onze producten kunt u vinden op onze
internationale website
.
Thuis
Zakelijk
Ondersteuning
Contact
Search
Summary
Full description
Statistics
Alias:
Worm/Readme
Type:
Worm
Size:
24.576 Bytes
Origin:
Date:
09-06-2001
Damage:
Sent by email.
VDF Version:
6.23.00.00
Danger:
Low
Distribution:
Low
Distribution
It sends itself by email using Microsoft Outlook. The email sent by the worm has the following structure:
Subject: As per your request!
Body: Please find attached file for your review I lokk forward to hear form your again very soon. Thank you.
Attachment: README.EXE
Technical Details
W32/Apost is an Internet worm, programmed in Visual Basic 6. If the worm is activated, a window appears indicating a false WinZip error message. When the user clicks on "Aceptar" button, the worm sends itself by email, using Microsoft Outlook Address Book. After sending emails, another window appears.
The worm creates copies of itself in Windows directory and in root directories of the local drives (C:\; D:\; ...) as README.EXE, which has the standard Visual Basic 6 application icon.
The worm makes the following registry entry:
HKCU\Software\Microsoft\Windows\Current Version\Run\macrosoft = %Windows%\Readme.exe
Description inserted by Crony Walker on dinsdag 15 juni 2004
Terug
.
.
.
.
Mijn Account
https
://
Dit venster is voor uw veiligheid gecodeerd.
Aanmelden
Wachtwoord vergeten
Reset wachtwoord
Mijn profiel
Producten
Betaalgeschiedenis
Meldingen
Wachtwoord resetten
Contact
Afmelden