Virus:Email-Worm.Win32.Warezov.bw
Other versions: .at ,.do , .et, .ex , .gl , .iq , .jv , .jx , .la , .lb , .lg , .ms , .mx , .nd , .nf , .ns , .nv , .oa , .oi
| Detection added |
Oct 02 2006 09:24 GMT |
| Update released |
Oct 02 2006 12:16 GMT |
| Description added |
Oct 03 2006 |
| Behavior |
Email Worm |
This worm spreads via the Internet as an attachment to infected messages. It sends itself to email addresses harvested from the victim machine.
The worm itself is a Windows PE EXE file 150 557 bytes in size, packed using UPack. The unpacked file is approximately 540KB in size.
Installation
Once launched, the worm causes the following message to be displayed:
When installing, the worm copies itself to the Windows root directory as “serv.exe”:
%Windir%\serv.exe It also creates the files listed below in the Windows root directory:
%System%\cssewmpd (16384 bytes)
%System%\e1.dll (8192 bytes)
%System%\regaufat.dll (24576 bytes)
%System%\wupstlnt.dll (28672 bytes)
%Windir%\serv.dll (7680 bytes)
%Windir%\serv.s
%Windir%\serv.wax
The worm also creates the following entries in the system registry to ensure that the worm file is run each time Windows is rebooted on the victim machine:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"serv"="%Windir%\serv.exe s"
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="wupstlnt.dll e1.dll"
Propagation via email
The worm sends itself to email addresses harvested from the MS Windows address books. It uses its own SMTP engine to send infected messages.
Infected messages
Example:
Message subject (chosen from the list below):
- Error
- Good Day
- hello
- Mail Delivery System
- Mail server report
- Mail Transaction Failed
- picture
- Server Report
- Status
Message body (chosen from the list below):
- Mail transaction failed. Partial message is available.
- The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
- The message contains Unicode characters and has been sent as a binary attachment.
-
Mail server report.
Our firewall determined the e-mails containing worm copies are being sent from your computer.
Nowadays it happens from many computers, because this is a new virus type (Network Worms).
Using the new bug in the Windows, these viruses infect the computer unnoticeably.
After the penetrating into the computer the virus harvests all the e-mail addresses
and sends the copies of itself to these e-mail addresses
Please install updates for worm elimination and your computer restoring.
Best regards,
Customers support service
The worm will terminate a range of antivirus and firewall applications.
It also contains a list of URLs, which it will check for the presence of files. If a file is placed on one of these URLs, the worm will download it to the victim machine and launch it for execution.
Detection for this variant of Warezov has already been released in an urgent update for Kaspersky Anti-Virus databases.
If 'Proactive Protection' is enabled, Kaspersky Anti-Virus 6.0 is able to detect this malicious program without an update to the antivirus databases.
- Reboot the computer in Safe Mode (at the start of the boot sequence, press and hold F8, then choose ‘Safe Mode' from the Windows boot menu. .
- Use Task Manager to search for the following process:
serv.ex
If such a process is found, terminate it.
- Manually delete the following files from the Windows root and system directories:
%System%\e1.dll
%System%\regaufat.dll
%System%\wupstlnt.dll
%System%\cssewmpd
%Windir%\serv.dll
%Windir%\serv.s
%Windir%\serv.wax
%Windir%\serv.exe
- Delete the following registry values:
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"serv"="%Windir%\serv.exe s"
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="wupstlnt.dll e1.dll"
- Reboot the computer as normal, and check that you have deleted all infected emails from all mail folders.
- Update your antivirus databases and perform a full scan of the computer ( download a trial version of Kaspersky Anti-Virus.)
|