









 | Win32/Finaldo.B Virus| Name | Win32/Finaldo.B Virus | | Aliases | Finaldo, Win32/Finaldo.B Virus | | Discovered on | 7th November 2001 |
Virus Information - Win32/Finaldo.B Virus:
This virus is found under 32-bit environment
(Windows 95, Windows98, Windows NT based systems). This virus also possess
worm characteristics. This virus spreads through email or file.
The virus arrives with a random subject
carrying an executable file attachment. The attachment file will have China
flag as its icon. The content of the mail will be blank. When the infected
mail is opened or previewed under Microsoft Outlook or Microsoft Outlook
Express, the virus gets activated. It drops Finaldoom.exe or Finaldoom.dll
into the Windows\Temp folder. It infects .EXE, .OCX and SCR files on local
and network drives by appending itself to the original file.
After this, it drops a file FINALDOOM.EML into Windows\Temp folder.
The virus gains access to the SMTP and sends mail to the existing recepients
in mailbox. It modifies .HTM, .HTML, and .ASP files on the local drives
with JavaScript that causes FINALDOOM.EML getting control.

|