This worm spreads via email and was found on Sep.9, 2009. Hauri Mail server has
received the tens of mails sent by worm and the
variant of this worm is spreadig.
Upon infection, worm downlowds and executes several URL defined inside worm, and creates winspf32.exe(18,200bytes) in thw Wondow
system folder. Worm retrieves email addresses from infected system and mass-mailing.
Infection method
Worm spreads itself with its own SMTP engine, the spreading object is searched and retrieved from the files that have the following
extentions in the infected system.