17 AprVirus News
Message theme: "RE: Britney Pics" Message text: Take a look at these pics ... Regards, %CurrentUser.Name%
Subject: You get off the ice and respect the referees decisionMessage body: Do you agree with the judge''s decision to disqualify a Korean skater and award Apolo Ohno the gold medal Wednesday night?Attachment name: SALTLAKE.jpg.vbs
HKLM\Software\Microsoft\Windows\CurrentVersion\Run Microsoft Diagnostic = %worm random EXE name%
Natasha.exe - 143K, virus dropper, was spammed to several email conferences in the middle of February 2002 Maria.doc.exe - 29K, this is the virus itself MacroSoftBL.exe - 70K, this is a fake anti-virus program (decoy)
File1: "PKGF320.exe" in Windows TEMP directory. File2: "MacroSoftBL.exe" in "Program Files\MacroSoftBL" directory, with Hidden and System attributes set on.
Windows\SCANREGW.EXE -> Windows\SYSTEM\SCANREGW.EXE