Virus:Email-Worm.Win32.Warezov.et

Other versions: .at , .bw , .do , .ex , .gl , .iq , .jv , .jx , .la , .lb , .lg , .ms , .mx , .nd , .nf , .ns , .nv , .oa , .oi

Aliases
Email-Worm.Win32.Warezov.et  ( Kaspersky Lab ) is also known as: W32/Stration.gen.dldr ( McAfee ),   Win32.HLLM.Limar.based ( Doctor Web ),   WORM/Stration.AF ( H+BEDV ),   Trojan.Dropper.Stration.VD ( SOFTWIN ),   Worm.Stration.WR ( ClamAV )
Detection added Oct 26 2006 17:50 GMT
Description added Jun 21 2007
Behavior Email Worm
Technical details

This worm spreads via the Internet as an attachment to infected messages. The attachment does not contain a copy of the worm, but a component which downloads other malicious programs via the Internet.

Infected messages will be sent to all email addresses harvested from the victim machine.

The worm itself is a Windows PE EXE file. The file is 64,512 bytes in size. It is packed using UPX. The unpacked file is approximately 150KB in size.

Installation

When launched, the worm copies its executable file to the Windows system directory as "mspradme.exe":

%System%\mspradme.exe

The worm also extracts DLL files from its body and saves them to the Windows system directory:

%System%\e1.dll
%System%\vb5dmspo.dll

In order to ensure that the worm components are launched automatically when the system is rebooted, the worm creates the following paremters in the system registry startup key:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"mspradme" = "%System%\mspradme.exe"

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs" = "<name of random system library>
vb5dmspo.dll e1.dll"

Propagation via email

The worm harvests email addresses from the MS Outlook address books.

The worm uses its own SMTP engine to send infected messages.

Infected messages

Message subject (chosen at random from the list below)

The message is chosen at random from the list below:

Error
Good Day
hello
Mail Delivery System
Mail server report
Mail Transaction Failed
picture
Server Report
Status
test

Message body (chosen at random from the list below)

The message is chosen at random from the list below:

Mail transaction failed. Partial message is available.

__________________________

The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.

__________________________

The message contains Unicode characters and has been sent as a binary attachment.

__________________________

Mail server report.

Our firewall determined the e-mails containing worm copies are being sent from your computer.

Nowadays it happens from many computers, because this is a new virus type (Network Worms).

Using the new bug in the Windows, these viruses infect the computer unnoticeably.
After the penetrating into the computer the virus harvests all the e-mail addresses
and sends the copies of itself to these e-mail addresses

Please install updates for worm elimination and your computer restoring.

Best regards,
Customers support service

Attachment name (chosen from the list below):

body
data
doc
docs
document
file
message
readme
test
text
Update-KB<random numbers>-x86

The attachment has a .zip or a txt.exe extension.

The attachment contains a component of the worm which is capable of downloading other malicious programs via the Internet.

Payload

The worm is able to terminate a range of processes, and to delete services related to antivirus solutions and firewalls.

The worm's main executable file will download other malicious programs from the remote malicious user's site and install them to the victim machine.

Removal instructions

If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:

  1. Use Task Manager to terminate the process associated with the original worm file.
  2. Delete the original worm file (the location will depend on how the program originally penetrated the victim machine).
  3. Manually delete the files listed below from the Windows system directory: %System%\vb5dmspo.dll %System%\mspradme.exe %System%\e1.dll
  4. Delete the following system registry key parameters:

    [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
    "mspradme" = "%System%\mspradme.exe"

    [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs" = "<name of random system library>
    vb5dmspo.dll e1.dll"

  5. Delete all infected messages from all mail folders.
  6. Update your antivirus databases and perform a full scan of the computer ( download a trial version of Kaspersky Anti-Virus).
 
HOME