W32/NewApt is an email worm discovered on Dec. 14, 1999.
AVERT has given it a risk assessment of High.
This worm arrives as an email attachment. The
body of the email appears differently depending
on whether the email client reads HTML. If it
does, the email text looks like this:
- ---------------------------------------
http://stuart.messagemates.com/index.html
Hypercool Happy New Year 2000 funny programs
and animations...
We attached our recent animation from this site
in our mail ! Check it out
- --------------------------------------
If the email client is not HTML-capable, the
message reads:
"he, your lame client cant read HTML, haha.
click attachment to see some stunningly HOT stuff"
The worm is in the attachment, which has a name
chosen randomly from the following list:
baby.exe, bboy.exe, boss.exe, casper.exe,
chestburst.exe, cooler1.exe, cooler3.exe, copier.exe,
cupid2.exe, farter.exe, fborfw.exe, goal.exe,
goal1.exe, g-zilla.exe, irngiant.exe, hog.exe,
monica.exe, panther.exe, panthr.exe, party.exe,
pirate.exe, s.exe, saddam.exe, theobbq.exe, video.exe.
If the worm is run, the following dummy error message
appears:
The dinamic link library giface.dll could not be found
in the specified path [list of directory names]
Note the misspelling of the word "dynamic".
If the worm detects that Outlook Express is installed,
it will search for messages received and build a list
of addresses. The next time Windows is booted, the
worm waits an unspecified amount of time and then
attempts to send itself to one of the addresses in
its list, using the format described above.
Get the EXTRA.DAT (newapt-4.zip) for McAfee VirusScan
4.0.25 and above. Get instructions on unzipping and
installing the EXTRA.DAT