This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
|
Minimum DAT
4312 (2003-12-31) Updated DAT4320 (2004-01-28) |
Minimum Engine
5.1.00 File Length23,552 |
Description Added
2003-12-29 Description Modified2003-12-30 |
This is an internet worm that spreads via email and network shares. The worm can also act as a backdoor using the IRC network.
When run, the worm copies itself as:
Where %WinSys% is the Windows system directory.
It modifies the following registry key in order to run itself at Windows startup:
The worm searches for email addresses by scanning the content of files with the following extensions:
The worm writes harvested email addresses to the file:
The worm uses its own SMTP engine to send emails. The email has the following characteristics:
Subject : (one of the following)
Attachment: (one of the following)
Body: (none)
The worm uses NetBIOS functions to connect to randomly generated IP addresses. It uses a predefined user name and password list to try to gain access. It generates large outbound connections to NetBIOS, port 139.
The worm connects to IRC server irc.undernet.org on port 6667. It uses randomly generated user name to login to a predefined channel. Once connected, it can listen for IRC commands and perform various backdoor activities, such as downloading and executing files.
- Existence of the files and registry keys mentioned above
- Unusual outbound connection to port 139
The worm spreads via SMTP mail and network shares.
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
But in some particular cases, the following steps need to be taken.
Please go to the Microsoft Recovery Console and restore a clean MBR.
On Windows XP:
On Windows Vista and 7: