Win32:MyParty
is a mass-mailing worm which does not have any destructive payload. It arrives in an infected email message which has the following characteristics:Subject: new photos from my party!
Body: Hello!
My party... It was absolutely amazing!
I have attached my web page with new photos!
If you can please make color prints of my photos. Thanks!
Attachment: www.myparty.yahoo.com (29,696 bytes long)
Although the attachment name looks like the website name, it is actually an executable file with a .COM extension.
This worm has very limited time frame in which it is able to spread. It is active only if the date is between 25th and 29th January 2002 (inlusive). During this period the worm copies itself to the file C:\Recycled\regctrl.exe and executes that file on Windows 9x/Me systems. On WinNT/2K/XP systems the worm copies itself to the file C:\regctrl.exe and it also drops the file MSSTASK.EXE in the STARTUP folder. This file is a Backdoor trojan.
Also the massmailing part of this worm is active during above mentioned period only. It retrieves the user's default SMTP gateway from registry and send itself to all addresses found in the Windows Address Book and addresses found within .DBX files using its own SMTP routine.
Variants:
Win32:MyParty-B is very similar worm. It's activity time frame
is between 20th and 24th January 2002. It also uses the slightly different
attachment name: myparty.photos.yahoo.com
Any avast! with VPS file dated on or after 28th January 2002 is able to detect this worm.







