Proactive IT Security
 

W32/Matcher@mm.28672

Threat risk

Threat risk low

Detection files published:
18 Apr 2001
Description created:
2001-04-18
Description updated:
2001-04-18

Malware type:
Worm
Alias:
Spreading mechanism
Email

Payload:

Spreading description

Email characteristics:

Subject: Matcher
Body: Want to find your love mates!!! Try this its cool... Looks and Attitude Maching to opposite sex.

Attachment: matcher.exe
This is a massmailing email worm written in Visual Basic 6 that spreads through Outlook. When it is executed it will send itself to email addresses taken from the Outlook Address book.

Threat description

It installs itself in the registry under the key

 

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
   Run (default) = \MATCHER.EXE

so that the worm is run every time the machine starts. An additional effect is that the following lines are inserted into the AUTOEXEC.BAT file:

 

@echo off
echo from: Bugger
pause

Thus, machines infected with this worm will show the message from: Buggeron the screen during startup and wait for the user to press a key. Since the worm is started every time the computer is started, this message can be entered repeatedly into AUTOEXEC.BAT.

Removal

General information about removal of malicious software

Norman's antivirus products are in general able to remove all malicious software that is detected.
Some malware, however, uses techniques that the general product does not remove sufficiantly. We have therefore developed the free product Norman Malware Cleaner. Please use the latest version of this program from the link below - if your Norman antivirus is unable to clean-up the infection.

Usage Title Comment
  Stopping network share infectors  
  Cleaning of back-up folders on Windows Me and XP