|
This Trojan displays a "HUGS
4 U" message the first time it is run. It also copies itself
to C:\WINDOWS\SYSHLP1.EXE and modifies C:\AUTOEXEC.BAT so
as to call itself every time the computer is restarted.
After about 6 restarts, the
Trojan puts a message in the Netscape InBox. The message claims
to be from "Secure Access Systems" and requests the user to
reply. This would appear to be an attempt to harvest emails
for spam mailing lists.
|