VBS/Waterworks.worm

This page shows details and results of our analysis on the malware VBS/Waterworks.worm

Overview

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.


Minimum DAT

4246 (2003-02-05)

Updated DAT

4449 (2005-03-17)

Minimum Engine

5.1.00

File Length

607 ini
7,246 vbs
12,037 htm

Description Added

2003-02-04

Description Modified

2003-02-04

Malware Proliferation

Characteristics

This VBScript worm overwrites files on the local system, and network drives. It also spread via the mIRC (Internet Relay Chat) application. It is not known to be in the wild. When run, the worm copies itself to the following files:
  • c:\Win32 Strt.exe.vbs
  • %WinDir%\jokes.htm (HTML version of the script)
  • %WinDir%\winupdate.exe (mIRC script)
  • %SysDir%\BootLoader.exe.vbs
  • %SysDir%\winhelp32.exe (HTML version of the script)
The following registry run keys are created:
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
    Run "BootLoader" = %SysDir%\BootLoader.exe.vbs
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
    RunServices "Win32 Strt.EXE" = \Win32 Strt.exe.vbs
The worm overwrites files, using the following extensions, on all local and mapped drives:
  • ASP
  • HTA
  • HTM
  • HTX
  • HTML
  • VBS
The mIRC SCRIPT.INI file is overwritten with code to send %WinDir%\jokes.htm to user upon joining the same channel as the infected user. This SCRIPT.INI file is detected as MIRC/Generic with the current DAT files.

Symptoms

The script has three date-activated payloads. On October 15:
    A message box entitled "my b-day" is displayed, reading "happy birthday kefi"
On November 23:
    A message box entitled "11/23!" is displayed, reading "holy sh*t! it's 11/23!"
On December 25:
    A message box entitled "kefi [rRlf]" is displayed, reading "Organized religion controls the world."
On all other days:
    A text document is saved on the desktop with the name "%day% - %month%.vir.txt", ie (4 - 2.vir.txt). The text reads:

    today you did not experience the payload of Vbs.Evion
    sorry..

    kefi [rRlf]

Method of Infection

This VBScript worm spreads to floppy diskettes, local, and remote drives by overwriting files. It also spreads via IRC.

Removal

All Users:
Use specified engine and DAT files for detection and removal.

Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

Additional Windows ME/XP removal considerations

Variants