Virus:Email-Worm.Win32.Warezov.jv

Other versions: .at , .bw , .do , .et, .ex, .gl, .iq, .jx , .la , .lb , .lg , .ms , .mx , .nd , .nf , .ns , .nv , .oa , .oi

Detection added Jan 15 2007 23:30 GMT
Update released Jan 16 2007 00:04 GMT
Description added Jan 17 2007
Behavior Email Worm
Technical details

This worm spreads via the Internet as an attachment to infected messages. The attachment does not contain a copy of the worm, but a component which will download the latest version of the worm via the Internet from a variety of sites.

The worm is a Windows PE EXE file 101,083 bytes in size. It is packed using UPX. The unpacked file is approximately 376KB in size.

Installation

When launched, the worm copies its executable file to the Windows directory as “tpup.exe”:

%WinDir%\tpup.exe

and then launches it with the 's' option.

It extracts the following file from its body:

%System%\e1.dll.

This file is 6144 bytes in size.

In order to ensure that its components are loaded the next time Windows is started, the worm creates the following parameters in the system registry:

[HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
tpup=%WinDir%\tpup.exe s

[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
AppInit_DLLs=<name of random system library> e1.dll

Propagation via email

The worm harvests addresses from the outlook address book and from files on the user's hard disk.

Harvested addresses will be saved to a file with the following name:

%WinDir%\tpup.wax
Payload
Propagation via email The worm harvests addresses from the outlook address book and from files on the user's hard disk. Harvested addresses will be saved to a file with the following name: %WinDir%\tpup.wax

Payload

The worm sends messages which contain a Trojan downloader in the attachment to email addresses harvested from the victim machine. This Trojan downloader will download the worm's main executable file from the Internet.

Message subject (chosen at random from the list below):

  • Error
  • Good Day
  • hello
  • Mail Delivery System
  • Mail server report
  • Mail Transaction Failed
  • picture
  • Server Report
  • Status
  • test

Message body (chosen at random from the list below):

  • Mail transaction failed. Partial message is available.
  • The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
  • The message contains Unicode characters and has been sent as a binary attachment.
  • Mail server report.

    Our firewall determined the e-mails containing worm copies are being sent from your computer.

    Nowadays it happens from many computers, because this is a new virus type (Network Worms).

    Using the new bug in the Windows, these viruses infect the computer unnoticeably. After the penetrating into the computer the virus harvests all the e-mail addresses and sends the copies of itself to these e-mail addresses

    Please install updates for worm elimination and your computer restoring.

    Best regards,
    Customers support service

Attachment name (will contain one of the following strings):

  • body
  • data
  • doc
  • docs
  • document
  • file
  • message
  • readme
  • test
  • text
  • Update-KB<random numbers>-x86

The attachement will have a .zip, a “doc.exe” or a “txt.exe” extension, which will have a large number of spaces in front of it.

The worm creates the following files:

%WinDir%\tpup.dat
%WinDir%\tpup.s

The worm component is the following file:

%System%\e1.dll

The worm code will be injected into randomly chosen processes on the victim machine. It is designed to disable antivirus protection.

The worm component attempts to terminate antivirus and personal firewall processes and to stop their services.

The worm also downloads a list of links to files on the Internet. It will then download files from these links, save them to the Windows temporary directory, and launch them.

Removal instructions

Urgent updates containing detection for this program have been released.

If you are using Kaspersky Anti-Virus 6.0, enable Proactive Protection and the solution will be able to detect and neutralize new variants without the need to update your antivirus databases.

If you do not have an up to date antivirus on your computer, and have been infected by this malicious program, you should follow the instructions below:

  1. Use Task Manager to terminate the worm process. (It may be callled tpup.exe).
  2. Delete the original worm file.
  3. Delete the following files:
    %WinDir%\tpup.exe
    %WinDir%\tpup.dat
    %WinDir%\tpup.s
    %WinDir%\tpup.wax
    %System%\e1.dll
  4. Delete the following parameters from the system registry:

    [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    tpup=%WinDir%\tpup.exe s

    [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    AppInit_DLLs=<name of random system library>e1.dll

  5. Update your antivirus databases and perform a full scan of your computer ( download a trial version of Kaspersky Anti-Virus.).
HOME