W32.Jonbarr.D@mm, which is a variant of the W32.Jonbarr@mm
worm, is a mass-mailing worm that uses its own SMTP engine to send itself to all the email addresses it finds in the .htm files and in temporary Internet files. Additionally, the worm attempts to terminate the processes of various antivirus programs.
The email has the following characteristics:
Microsoft Windows Patch
From: "Microsoft" <email@example.com>
Reply-To: "Microsoft" <firstname.lastname@example.org>
Message: Please open the attachment if want to get supprise!
When the attachment is opened, W32.Jonbarr.D@mm displays the message:
Happy Birthday My!
W32.Jonbarr.D@mm is written in the Microsoft C++ programming language and is compressed with UPX.
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.