Symantec.com > Enterprise > Security Response > W32.Modnar.Worm@mm

W32.Modnar.Worm@mm

Risk Level 1: Very Low

Discovered:
August 14, 2001
Updated:
February 13, 2007 11:47:17 AM
Also Known As:
W32/Modnar
Type:
Worm

W32.Modnar.Worm@mm is a mass-mailing worm that appears to be written in C++. When executed, the worm extracts all of the email address from the Windows Address Book (WAB). The worm then emails a copy of itself to all of the extracted email addresses.



What are Portable Executable (PE) files?
PE files are files that are portable across all Microsoft 32-bit operating systems. The same PE-format executable can be run on any version of Windows 95, 98, Me, NT, and 2000. All PE files are executable, but not all executable files are portable.

Antivirus Protection Dates

  • Initial Rapid Release version August 14, 2001
  • Latest Rapid Release version August 20, 2008 revision 017
  • Initial Daily Certified version August 14, 2001
  • Latest Daily Certified version August 20, 2008 revision 016
  • Initial Weekly Certified release date pending
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Low

Distribution

  • Distribution Level: Medium
Writeup By: Neal Hindocha

Search Threats

Search by name

Example: W32.Beagle.AG@mm
ThreatCon Widget
Internet Security Threat Report, Volume 16
Symantec DeepSight Screensaver