Additional Details
When an user opens the spammed email, an attept to download and execute a
VBS/Inor dropper is made. If the dropper is able to execute, then a variant
of W32/Dumaru worm is installed into system. Inor drops the worm to
"C:\2.exe".
We have received reports that different variants of W32/Dumaru have been
dropped from the web site. Further information about W32/Dumaru is available
within the following descriptions:
http://www.f-secure.com/v-descs/dumaru_y.shtml
http://www.f-secure.com/v-descs/dumaru_z.shtml
At the time of writing this description, the trojan downloader is removed
from the web site.
Below is a screenshot of the message:
Detection
Detection in F-Secure Anti-Virus was published on January 26th, 2004 at
early morning in update:
[FSAV_Database_Version]
Version=2004-01-26_01
Technical Details:
Katrin Tocheva and Sami Rautiainen, January 26th, 2004;
F-Secure Corporation