On January 24th and 25th, 2004, a number of emails with a fake virus warning
from Microsoft were spammed. When users view the email it
attempts to download and execute a variant of VBS/Inor trojan dropper from a
web site. The real address has been spoofed using a security vulnerability
in Internet Explorer.
Detailed Description
When an user opens the spammed email, an attept to download and execute a
VBS/Inor dropper is made. If the dropper is able to execute, then a variant
of W32/Dumaru worm is installed into system. Inor drops the worm to
"C:\2.exe".