Symantec.com > Enterprise > Security Response > W32.Jonbarr.C@mm

W32.Jonbarr.C@mm

Risk Level 2: Low

Discovered:
November 8, 2002
Updated:
February 13, 2007 11:49:56 AM
Also Known As:
Worm_Pibi.B
Type:
Worm
Systems Affected:
Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP


W32.Jonbarr.C@mm is a variant of the W32.Jonbarr@mm worm. It is a mass-mailing worm that uses its own SMTP engine to send itself to all the email addresses it finds in the .htm files and in the temporary Internet files.

This worm also attempts to spread across the mIRC, KaZaA, eDonkey2000, Bearshare, and Morpheus file-sharing networks. The email message has the following characteristics:

Subject:
WindowsXP Service Release Pack 2.002
or
Re:hya

From: "Microsoft" <support@microsoft.com>
Reply-To: "Microsoft" <microsoft@microsoft.com>
Message: Istall the program in the attachment.
Attachment: Install.exe

If the current system date is October 18, W32.Jonbarr.C@mm will display a message with the title, "I-Worm/PiecebyPiece.B by MI_pi..."

W32.Jonbarr.C@mm is written in the Microsoft C++ programming language and is compressed with UPX.

Antivirus Protection Dates

  • Initial Rapid Release version November 11, 2002
  • Latest Rapid Release version November 11, 2002
  • Initial Daily Certified version November 11, 2002
  • Latest Daily Certified version November 11, 2002
  • Initial Weekly Certified release date November 13, 2002
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Low

Distribution

  • Distribution Level: Low
Writeup By: Yana Liu

Search Threats

Search by name

Example: W32.Beagle.AG@mm
ThreatCon Widget
Internet Security Threat Report, Volume 16
Symantec DeepSight Screensaver