W32.Gibe.B@mm is a variant of
W32.Gibe@mm. This mass-mailing worm uses Microsoft Outlook and its own SMTP engine to send itself to all the contacts in the Microsoft Outlook Address Book and the Windows Address Book. The email is disguised as a Microsoft Security Update and it arrives with an attachment that has a .exe or .zip file extension.
W32.Gibe.B@mm copies itself as WebLoader.exe to the startup folder of all the mapped remote drives. This worm also attempts to spread through the KaZaA file-sharing network and Internet Relay Chat (IRC). W32.Gibe.B@mm may send itself to some news groups whose URLs are carried by the worm.
This threat is written in the Microsoft Visual Basic programming language.
NOTE: Virus definitions dated on February 25, 2003 may detect this threat as W32.Gibe@mm.
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.