Virus Name  : W32.Prolin@mm

Alias             : I-Worm.Prolin, W32.Prolin-A, WORM_PROLIN.A

Virus type    : Internet worm

Threat level : Low

Virus details :

                     Prolin is an Internet worm, uses Microsoft Outlook to email itself. The worm is 36,834 bytes long {37and written in Visual Basic 6. It needs "MSVBVM60.dll" to spread otherwise it will show DLL missing error. The e-mail attachment name will be "Creative.exe".

                     While opening the e-mail attachment, the worm will copy "Creative.exe" to root directory of C drive and Windows startup folder C:\WINDOWS dir\Start Menu\Programs\Startup\Creative.exe. So the creative.exe file is loaded automatically whenever the system is started.

                     It opens the Microsoft Outlook Address book and sends email to all the email Ids stored. The message subject will be "A great Shockwave flash movie", the message body will be "Checkout this new flash movie that i downloaded just now... It's Great. Bye" and the attachment name will be "Creative.exe". It will show similar icon to the shockwave movie.

                     After that it will send a notification message to the virus author with subject "Job complete". It send this message to a yahoo id with message body "Got yet another idiot".

                     The payload of this worm is somewhat different. It searches for files with extensions *.ZIP, *.MP3 and *.JPG and moves them to the C drive root directory. It also adds the string "Change atleast now to LINUX" to each file extension. For example XYZ.JPG will be renamed to XYZ.JPGchange atleast now to LINUX.

                     The worm also creates a file "C:\messageforu.txt" in the root directory of C drive and stores the moved files information. At the start of this file it stores the following text strings.

"Hi, guess you have got the message. I have kept a list of files that I have infected under this. If you are smart enough just reverse back the process. i could have done far better damage, i could have even completely wiped your harddisk. Remember this is a warning & get it sound and clear... - The Penguin"

How can I protect my system?

