JS/Flea@M

This page shows details and results of our analysis on the malware JS/Flea@M

Overview

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.


Minimum DAT

4299 (2003-10-22)

Updated DAT

4299 (2003-10-22)

Minimum Engine

5.1.00

File Length

Varies

Description Added

2003-10-24

Description Modified

2003-10-24

Malware Proliferation

Characteristics

This threat is considered to be a Low-Profiled risk due to media attention at:
http://www.theregister.co.uk/content/56/33569.html .

This threat is detected as JS/Fortnight@M .  This virus spreads by inserting a snippet of HTML code into every message sent through Microsoft Outlook Express. This is accomplished by creating a new HTML file, and setting it as the default signature file used by Outlook Express.

The virus is received as HTML code in any email message. This code uses an IFRAME tag with the SRC set to a remote website. When the message is accessed, that remote site is contacted.

The worm makes several Internet Explorer setting changes, designed to drive the user to the virus author's website, seemingly for advertisement purposes. Such program tactics used for this purpose are sometimes refered to as "scumware":

  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search "SearchAssistant" 
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search "CustomizeSearch"
  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
    CurrentVersion\URL\DefaultPrefix 
  • HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\ "SearchURL"

The virus also creates the following buttons on the Internet Explorer toolbar:

  • SEARCH
  • ANTIVIRUS
  • PILLS
  • SECURITY

Symptoms

Unusual HTML signature in each email message sent from the infected system.

Method of Infection

This virus spreads via email. One an infected message is received, additional components are downloaded and the system is configured to be a carrier of the virus.

Removal

All Users:
Use current engine and DAT files for detection. Delete any file which contains this detection.

Additional Windows ME/XP removal considerations

Variants