Additional Details
The messages the worm sends have randomly chosen Subject: line
but the attachment name is fixed ('BINLADEN_BRASIL.EXE').
When the attachment is executed it infects 'hh.exe' (HTML Help
executable) and 'explorer.exe' in the windows directory. The
worm body is dropped to the Windows directory with a random
three character long name. This file is added to 'system.ini':
[boot]
shell=Explorer.exe XXX.exe
Payload
The worm does not have a destructive payload. After starting sometimes
it displays a message.
[Analysis: Gergely Erdelyi; F-Secure Corp.; 24 of October, 2001]