Virus:Email-Worm.Win32.Warezov.bw

Other versions: .at ,.do , .et, .ex , .gl , .iq , .jv , .jx , .la , .lb , .lg , .ms , .mx , .nd , .nf , .ns , .nv , .oa , .oi

Detection added Oct 02 2006 09:24 GMT
Update released Oct 02 2006 12:16 GMT
Description added Oct 03 2006
Behavior Email Worm
Technical details

This worm spreads via the Internet as an attachment to infected messages. It sends itself to email addresses harvested from the victim machine.

The worm itself is a Windows PE EXE file 150 557 bytes in size, packed using UPack. The unpacked file is approximately 540KB in size.

Installation

Once launched, the worm causes the following message to be displayed:

When installing, the worm copies itself to the Windows root directory as “serv.exe”:

%Windir%\serv.exe

It also creates the files listed below in the Windows root directory:

%System%\cssewmpd (16384 bytes)
%System%\e1.dll (8192 bytes)
%System%\regaufat.dll (24576 bytes)
%System%\wupstlnt.dll (28672 bytes)
%Windir%\serv.dll (7680 bytes)
%Windir%\serv.s
%Windir%\serv.wax

The worm also creates the following entries in the system registry to ensure that the worm file is run each time Windows is rebooted on the victim machine:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
  "serv"="%Windir%\serv.exe s"

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
  "AppInit_DLLs"="wupstlnt.dll e1.dll"

Propagation via email

The worm sends itself to email addresses harvested from the MS Windows address books. It uses its own SMTP engine to send infected messages.

Infected messages

Example:

Message subject (chosen from the list below):

  • Error
  • Good Day
  • hello
  • Mail Delivery System
  • Mail server report
  • Mail Transaction Failed
  • picture
  • Server Report
  • Status

Message body (chosen from the list below):

  • Mail transaction failed. Partial message is available.
  • The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
  • The message contains Unicode characters and has been sent as a binary attachment.
  • Mail server report.

    Our firewall determined the e-mails containing worm copies are being sent from your computer.

    Nowadays it happens from many computers, because this is a new virus type (Network Worms).

    Using the new bug in the Windows, these viruses infect the computer unnoticeably.
    After the penetrating into the computer the virus harvests all the e-mail addresses
    and sends the copies of itself to these e-mail addresses

    Please install updates for worm elimination and your computer restoring.

    Best regards,
    Customers support service

Payload

The worm will terminate a range of antivirus and firewall applications.

It also contains a list of URLs, which it will check for the presence of files. If a file is placed on one of these URLs, the worm will download it to the victim machine and launch it for execution.

Removal instructions

Detection for this variant of Warezov has already been released in an urgent update for Kaspersky Anti-Virus databases.

If 'Proactive Protection' is enabled, Kaspersky Anti-Virus 6.0 is able to detect this malicious program without an update to the antivirus databases.

  1. Reboot the computer in Safe Mode (at the start of the boot sequence, press and hold F8, then choose ‘Safe Mode' from the Windows boot menu. .
  2. Use Task Manager to search for the following process:
    serv.ex
    If such a process is found, terminate it.
  3. Manually delete the following files from the Windows root and system directories:
    %System%\e1.dll
    %System%\regaufat.dll
    %System%\wupstlnt.dll
    %System%\cssewmpd
    %Windir%\serv.dll
    %Windir%\serv.s
    %Windir%\serv.wax
    %Windir%\serv.exe
  4. Delete the following registry values:

    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
      "serv"="%Windir%\serv.exe s"

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"="wupstlnt.dll e1.dll"

  5. Reboot the computer as normal, and check that you have deleted all infected emails from all mail folders.
  6. Update your antivirus databases and perform a full scan of the computer ( download a trial version of Kaspersky Anti-Virus.)
HOME