I-Worm.Bagle.y
Description I-Worm.Bagle.y
This worm spreads via the Internet as an attachment to infected messages. The worm itself is a PE EXE file of approximately 38KB, packed using UPX. The unpacked file is approximately 70KB in size. Characteristics of infected messages Sender's address (chosen at random from the following): annie ann christina christy jessie lizie secretGurl Message header (chosen at random from the following): Encrypted document Fax Message Received Forum notify Hello! Hey! Hidden message I just need a friend I like you I'm a sad girlall I'm bored with this life Incoming message Let's socialize, my friend! Let's talk, my friend! Notify from a known person ;-) Protected message Re: Document Re: Hello Re: Hi Re: Incoming Fax Re: Incoming Message Re: Msg reply RE: Protected message RE: Text message Re: Thank you! Re: Thanks :) Re: Yahoo! Request response Site changes Message body: There is a wide range of possible message texts. The message may contain a VBS script; if this is launched by the user, it exploits a Microsoft Internet Explorer vulnerability (defined in Microsoft Security Bulletin MS03-040) which makes it possible to download the executable worm file via the Internet from several dozen infected web sites. Attachment name: Random, with one of the following extensions: .exe .com .scr .cpl. hta .vbs .zip Installation Once launched, the worm copies itself to the Windows system directory under the name "drvsys.exe", and registers this file in the system registry autorun key: [HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun] "drvsys.exe" = "%system%drvsys.exe" and creates the following files in the Windows system directory drvsys.exeopen drvsys.exeopenopen When starting, the worm displays the message shown below:
The worm searches the system register for keys created by other worms (e.g. Netsky) and deletes them: 9XHtProtect Antivirus EasyAV FirewallSvr HtProtect ICQ Net ICQNet Jammer2nd KasperskyAVEng MsInfo My AV NetDy Norton Antivirus AV PandaAVEngine service Special Firewall Service SysMonXP Tiny AV Zone Labs Client Ex The worm also attempts to connect to a range of remote sites, and to save information about the victim computer on these sites. Propagation The worm searches the computer for files with the following extensions: adb asp cfg cgi dbx dhtm eml htm jsp mdx mbx mht mmf msg nch ods oft php pl sht shtm stm tbb txt uin wab wsh xls xml
and sends itself to all email addresses found in these files. It uses its own SMTP-server to send messages. Propagation via P2P The worm searches the computer for folders where the name contains the word 'shar' and copies itself several times to each folder found, under the following names: ACDSee 9.exe Adobe Photoshop 9 full.exe Ahead Nero 7.exe Kaspersky Antivirus 5.0 KAV 5.0 Matrix 3 Revolution English Subtitles.exe Microsoft Office 2003 Crack, Working!.exe Microsoft Office XP working Crack, Keygen.exe Microsoft Windows XP, WinXP Crack, working Keygen.exe Opera 8 New!.exe Porno pics arhive, xxx.exe Porno Screensaver.scr Porno, sex, oral, anal cool, awesome!!.exe Serials.txt.exe WinAmp 5 Pro Keygen Crack Update.exe WinAmp 6 New!.exe Windown Longhorn Beta Leak.exe Windows Sourcecode update.doc.exe XXX hardcore images.exe Remote administration The worm opens port 2535 and tracks port activity. The backdoor function makes it possible to remotely execute commands and download files to the victim machine. Other The worm attempts to combat antivirus programs and firewalls by terminating the following memory processes: AGENTSVR.EXE ANTI-TROJAN.EXE ANTIVIRUS.EXE ANTS.EXE APIMONITOR.EXE APLICA32.EXE APVXDWIN.EXE ATCON.EXE ATGUARD.EXE ATRO55EN.EXE ATUPDATER.EXE ATWATCH.EXE AUPDATE.EXE AUTODOWN.EXE AUTOTRACE.EXE AUTOUPDATE.EXE AVCONSOL.EXE AVGSERV9.EXE AVLTMAIN.EXE AVprotect9x.exe AVPUPD.EXE AVSYNMGR.EXE AVWUPD32.EXE AVXQUAR.EXE BD_PROFESSIONAL.EXE BIDEF.EXE BIDSERVER.EXE BIPCP.EXE BIPCPEVALSETUP.EXE BISP.EXE BLACKD.EXE BLACKICE.EXE BOOTWARN.EXE BORG2.EXE BS120.EXE CDP.EXE CFGWIZ.EXE CFIADMIN.EXE CFIAUDIT.EXE CFINET.EXE CFINET32.EXE CLEAN.EXE CLEANER.EXE CLEANER3.EXE CLEANPC.EXE CMGRDIAN.EXE CMON016.EXE CPD.EXE CPF9X206.EXE CPFNT206.EXE CV.EXE CWNB181.EXE CWNTDWMO.EXE DEFWATCH.EXE DEPUTY.EXE DPF.EXE DPFSETUP.EXE DRWATSON.EXE DRWEBUPW.EXE ENT.EXE ESCANH95.EXE ESCANHNT.EXE ESCANV95.EXE EXANTIVIRUS-CNET.EXE FAST.EXE FIREWALL.EXE FLOWPROTECTOR.EXE FP-WIN_TRIAL.EXE FRW.EXE FSAV.EXE FSAV530STBYB.EXE FSAV530WTBYB.EXE FSAV95.EXE GBMENU.EXE GBPOLL.EXE GUARD.EXE GUARDDOG.EXE HACKTRACERSETUP.EXE HTLOG.EXE HWPE.EXE IAMAPP.EXE IAMSERV.EXE ICLOAD95.EXE ICLOADNT.EXE ICMON.EXE ICSSUPPNT.EXE ICSUPP95.EXE ICSUPPNT.EXE IFW2000.EXE IPARMOR.EXE IRIS.EXE JAMMER.EXE KAVLITE40ENG.EXE KAVPERS40ENG.EXE KERIO-PF-213-EN-WIN.EXE KERIO-WRL-421-EN-WIN.EXE KERIO-WRP-421-EN-WIN.EXE KILLPROCESSSETUP161.EXE LDPRO.EXE LOCALNET.EXE LOCKDOWN.EXE LOCKDOWN2000.EXE LSETUP.EXE LUALL.EXE LUCOMSERVER.EXE LUINIT.EXE MCAGENT.EXE MCUPDATE.EXE MFW2EN.EXE MFWENG3.02D30.EXE MGUI.EXE MINILOG.EXE MOOLIVE.EXE MRFLUX.EXE MSCONFIG.EXE MSINFO32.EXE MSSMMC32.EXE MU0311AD.EXE NAV80TRY.EXE NAVAPW32.EXE NAVDX.EXE NAVSTUB.EXE NAVW32.EXE NC2000.EXE NCINST4.EXE NDD32.EXE NEOMONITOR.EXE NETARMOR.EXE NETINFO.EXE NETMON.EXE NETSCANPRO.EXE NETSPYHUNTER-1.2.EXE NETSTAT.EXE NISSERV.EXE NISUM.EXE NMAIN.EXE NORTON_INTERNET_SECU_3.0_407.EXE NPF40_TW_98_NT_ME_2K.EXE NPFMESSENGER.EXE NPROTECT.EXE NSCHED32.EXE NTVDM.EXE NUPGRADE.EXE NVARCH16.EXE NWINST4.EXE NWTOOL16.EXE OSTRONET.EXE OUTPOST.EXE OUTPOSTINSTALL.EXE OUTPOSTPROINSTALL.EXE PADMIN.EXE PANIXK.EXE PAVPROXY.EXE PCC2002S902.EXE PCC2K_76_1436.EXE PCCIOMON.EXE PCDSETUP.EXE PCFWALLICON.EXE PCIP10117_0.EXE PDSETUP.EXE PERISCOPE.EXE PERSFW.EXE PF2.EXE PFWADMIN.EXE PINGSCAN.EXE PLATIN.EXE POPROXY.EXE POPSCAN.EXE PORTDETECTIVE.EXE PPINUPDT.EXE PPTBC.EXE PPVSTOP.EXE PROCEXPLORERV1.0.EXE PROPORT.EXE PROTECTX.EXE PSPF.EXE PURGE.EXE PVIEW95.EXE QCONSOLE.EXE QSERVER.EXE RAV8WIN32ENG.EXE REGEDIT.EXE REGEDT32.EXE RESCUE.EXE RESCUE32.EXE RRGUARD.EXE RSHELL.EXE RTVSCN95.EXE RULAUNCH.EXE SAFEWEB.EXE SBSERV.EXE SD.EXE SETUP_FLOWPROTECTOR_US.EXE SETUPVAMEEVAL.EXE SFC.EXE SGSSFW32.EXE SH.EXE SHELLSPYINSTALL.EXE SHN.EXE SMC.EXE SOFI.EXE SPF.EXE SPHINX.EXE SPYXX.EXE SS3EDIT.EXE ST2.EXE SUPFTRL.EXE SUPPORTER5.EXE SYMPROXYSVC.EXE SYSEDIT.EXE TASKMON.EXE TAUMON.EXE TAUSCAN.EXE TC.EXE TCA.EXE TCM.EXE TDS2-98.EXE TDS2-NT.EXE TDS-3.EXE TFAK5.EXE TGBOB.EXE TITANIN.EXE TITANINXP.EXE TRACERT.EXE TRJSCAN.EXE TRJSETUP.EXE TROJANTRAP3.EXE UNDOBOOT.EXE UPDATE.EXE VBCMSERV.EXE VBCONS.EXE VBUST.EXE VBWIN9X.EXE VBWINNTW.EXE VCSETUP.EXE VFSETUP.EXE VIRUSMDPERSONALFIREWALL.EXE VNLAN300.EXE VNPC3000.EXE VPC42.EXE VPFW30S.EXE VPTRAY.EXE VSCENU6.02D30.EXE VSECOMR.EXE VSHWIN32.EXE VSISETUP.EXE VSMAIN.EXE VSMON.EXE VSSTAT.EXE VSWIN9XE.EXE VSWINNTSE.EXE VSWINPERSE.EXE W32DSM89.EXE W9X.EXE WATCHDOG.EXE WEBSCANX.EXE WGFE95.EXE WHOSWATCHINGME.EXE WINRECON.EXE WNT.EXE WRADMIN.EXE WRCTRL.EXE WSBGATE.EXE WYVERNWORKSFIREWALL.EXE XPF202EN.EXE ZAPRO.EXE ZAPSETUP3001.EXE ZATUTOR.EXE ZAUINST.EXE ZONALM2601.EXE ZONEALARM.EXE
Check other viruses! Be aware! Use Antiviral Software
Macro.Word97.Zmk
Description Macro.Word97.Zmk
This virus contains five macros in one module "ZMK98FAV": AutoOpen, FileSaveAs, FileTemplates, ToolsMacro, ViewVBCode. It infects the global macros area on opening an infected document and infects documents on saving with a new name. The virus then searches and infects documents in the current directory. The virus displays the MessageBoxes: ZMK98FAV Je suis un nouveau AntiVirus pour Word 97 ZMK98FAV Vous feriez mieux d'acheter un VRAI ANTIVIRUSall HAHA !!!!!
Macro.Word97.ZMK.J
Description Macro.Word97.ZMK.J
Analysis by and (c) Paolo Monti This macro-virus was written in VBA (Visual Basic for Applications) for MS Word 8.0 (Office 97). It contains very dangerous payloads, and it displays message and dialogue boxes concerning the World Cup Soccer Championship France 98. The VBA project of the virus contains one form named Pronostic and a module implementing 8 different macros: AutoExec: calls the macro Pronostique or WC98Payload (see below). AutoOpen: infects the global template and displays a messagebox. FileSaveAs: infects new documents, saving them as templates, and displays a messagebox. FileTemplates: displays a messagebox. Pronostique: displays a dialogue box where the user is forced to make a choice, and implements a number of different payloads. ToolsMacro: displays a messagebox, ViewVBCode: shows the MS Word Assistant displaying a message, WC98Payload: modifies the contents of an active document. The following instructions can be found at the beginning of all macros: Disable the possibility to interrupt macro execution Enable the execution of automatic macros Disable the antivirus protection built in Ms Word Disable the confirmation for the global template saving, usually asked before exiting from the program. The automatic macro AutoExec, executed at the startup of MS Word or when a general template is loaded, gets the current system date and time. If the day number is 12 or the seconds of the system clock are at 12, the AutoExec macro calls the macro Pronostique or the macro WC98Payload. The choice between the two macros is applied randomly. Each has a 50% probability to be called from AutoExec macro. The macro Pronostique displays a dialogue box on the screen (the form Pronostic) by which the user is asked to choose among 9 different teams partecipating in the France 98 Championship. If the user chooses the same team selected randomly by the virus, a messagebox of congratulations is displayed on the screen, then the virus goes into an endless loop showing a message in the status bar. Otherwise, the virus applies a randomly selected payload. With a probability of 40%, the virus appends the following lines to the file C:AUTOEXEC.BAT: cls Echo La coupe du monde 98 c'est gÊnial!!!! Echo y|Format c: /u /v:WorldCup98 Echo o|Format c: /u /v:WorldCup98
27% of the time, the virus tries to delete all files in the directories C:DOS and C:WINDOWSCOMMAND and the files C:MSDOS.SYS and C:IO.SYS. In the remaining cases, the virus modifies the text of the active document and prints it. The macro WC98Payload creates in the active document a WordArt object, applies to it a number of rotation effects, and then erases it. Inside the project of the virus there are some messages in French: "VIVE LA COUPE DU MONDE 98!!!!" "Vive le football!!!, Vive la Coupe du Monde 98!!!"
AVP detects/disinfects this virus since weekly update 980706
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|