"Funny" Worm with a Trojan in its Pocket

15 Sep 2000
Virus News

Kaspersky Lab Int., an international anti-virus software vendor, reports the detection of another Internet-worm "I-Worm.Funny". The virus has been reported to be "in-the-wild" in Switzerland.

General Characteristics

This is an Internet worm written in the scripting language "Visual Basic Script" (VBS). The worm uses MS Oulook to spread its copies by e-mail. Upon activation, the worm sends its copy to all recipients from the MS Outlook address list. The infected message has only the subject line "Funny story" and the attached file "FUNNY_STORY.HTM.vbs" that is the worm itself. Depending on system settings, the actual extension of the attached file (.vbs) may not be displayed.

The worm carries the Trojan program code of Trojan.PSW.Hooker. After spreading, the worm writes this program onto a disk and starts it.