This worm arrives as an email message with the following content:
Subject: The subject of the email will be random, and could be the same as
the file name of the attachment in the email.
Attachment: The attachment will be a file taken from the sender's computer
and will have the extension .bat, .com, .lnk or .pif added to it.
Message: The message body will be semi-random, but will always contain one of
the following two lines (either English or Spanish) as the first and last
sentences of the message.
Spanish Version:
First line: Hola como estas ?
Last line: Nos vemos pronto, gracias.
English Version:
First line: Hi! How are you?
Last line: See you later. Thanks
Between these two sentences, some of the following text may appear:
Spanish Version:
Te mando este archivo para que me des tu punto de vista
Espero me puedas ayudar con el archivo que te mando
Espero te guste este archivo que te mando
Este es el archivo con la informaci=n que me pediste
English Version:
I send you this file in order to have your advice
I hope you can help me with this file that I send
I hope you like the file that I sendo you
This is the file with the information that you ask for
Please advise all users not to open any attachments with the above contents.
The most current Norton definition file dated 7/18/01 will detect this worm
and delete it if the client option is set at the Parent level.
Also, The GroupWise Internet Gateway is set to delete the Virus and all file
extensions and variants known at this time,
although we have had several reports of the virus getting through the Gateway
and being caught by the P.C. client.
We are investigating this now.