This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
|
Minimum DAT
4310 (2003-12-21) Updated DAT4633 (2005-11-21) |
Minimum Engine
5.1.00 File Length54,784 bytes |
Description Added
2003-12-18 Description Modified2003-12-18 |
-- Update 18th December 2003 --
This threat is considered to be a Low-Profiled risk due to media attention at:
http://www.pcworld.idg.com.au/index.php?id=1125097465&fp=2&fpid=1
This detection is for a mass-mailing worm written in Visual Basic. Similar to its predecessor (W32/Sober.a@MM ) the worm bears the following characteristics:
Mail Propagation
The worm extracts target email addresses from the victim machine, and writes them to the file MSCOLMON.OCX in the %SysDir% . For example:
Outgoing messages are constructed using the worm's own SMTP engine. The messages may be written in either English or German, and the attachment may be of varying filename.
Messages are formatted with various subject lines, body contents and attachment filenames. These include the following examples:
Subject Lines:
Attachment:
Installation
Upon execution, one of various possible fake error messages are displayed. For example:
The worm installs itself into %SysDir% on the victim machine:
Additionally, and in common with W32/Sober.a@MM , two other copies of the worm are dropped into %SysDir% , with varying filename. For example:
These two latter files are responsible for monitoring and maintaining that the worm stays resident in memory. Upon termination of one worm processes, another copy will restart the terminated process very quickly.
System startup is hooked via the two Registry keys, hooking one of these latter copies of the worm. For example:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run "(string)" = %SysDir%\ENDSVC.EXE
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run "(string)" = %SysDir%\ENDSVC.EXE
Where "string" varies between infections.
The following file is also dropped to the victim machine (0 bytes in testing):
This worm is intended to propagate via emailing itself to email addresses extracted from the victim machine.
It constructs outgoing messages (with varying subject lines, attachment names and message bodies) using its own SMTP engine.
As with its predecessor, this variant employs two processes on the victim machine in an attempt to avoid its termination. When one process is killed, the other immediately restarts it.
All Users
:
AVERT considers this to be a low risk threat.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).