W32.Row@mm

Discovered:
September 21, 2001
Updated:
February 13, 2007 12:12:42 PM
Also Known As:
W32/Pony.worm[McAfee], I-Worm.PonyExpress[KAV], WORM_PNYXPRESS.A[Trend], W32/PonyExpr[Sophos]
Type:
Worm
Systems Affected:
Microsoft IIS, Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

W32.Row@mm is a mass-mailing worm that uses Microsoft Outlook to send itself to all the contacts in the Outlook Address Book.

The email has the following characteristics:

Subject: Fw: Security note #526272
Message:
--------------- This is a forwarded message ---------------
> Original message from <support@af-solutions.com.uk>
> Dear custommer.
> Please read the attached data security note #526272/C.
> As a registered user of our data security / antivirus suite,
> we send you the latest security information. It is highly recommended
> that you read the information card and keep it in a safe place.
> Note also that you may freely distribute the card to your friends
> and collegues which is highly recommended too.
> If you do not wish to receive any further information, please read
> the file for instructions.
> At your service:
> Dr. Ivor Davis
> Senior researcher.
> Artificial Solutions Corp.
> Birmingham B42 2PA. UK.
> 12 Winston Road, Olton,
Attachment: security.exe

The worm also attempts to spread itself through the IIS Web server by tricking the users into downloading the worm.

This threat is written in the Microsoft Visual Basic programming language. It may be compressed with PECompact.

Antivirus Protection Dates

  • Initial Rapid Release version September 23, 2001
  • Latest Rapid Release version September 28, 2010 revision 054
  • Initial Daily Certified version September 23, 2001
  • Latest Daily Certified version September 28, 2010 revision 036
  • Initial Weekly Certified release date September 26, 2001
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Yana Liu

Search Threats

Search by name

Example: W32.Beagle.AG@mm
ThreatCon Widget
Internet Security Threat Report, Volume 16
Symantec DeepSight Screensaver