This worm spreads via the Internet as an attachment to infected messages.
The worm itself is a Windows PE EXE file approximately 11KB in size. It is packed using FSG, and the unpacked file is approximately 25KB in size.
Infected messages
Message subject (chosen at random from the list below):
Happy New Year!
Merry X-Mas!
Message body (chosen at random from the list below):
Happy New year and wish you good luck on next year!
Mery Chrismas & Happy New Year! 2005 will be the beginning!
Attachment name
bat
com
pif
scr
The worm is only launched if the user opens the attachment. Atak.h will then install itself to the system and start propagating.
It will not repeatedly install itself to memory.
Installation
When installing, the worm copies itself as dec25.exe to the Windows system directory. It modifies the win.ini file, and adds the file name dex25.exe to the run key in [windows]:
[windows]
run=%SystemDir%\dec25.exe
This ensures that a copy of the worm will be launched each time the infected computer is rebooted.
Mass mailing
The worm searches for files with the following extensions:
asp
dbx
eml
htm
jsp
mht
msg
php
txt
It harvests email addresses from these files, and sends a copy of itself by establishing a direct connection to the SMTP server.
Check out if we have free
removal tool for this virus