Virus:Email-Worm.Win32.Warezov.jvOther versions: .at , .bw , .do , .et, .ex, .gl, .iq, .jx , .la , .lb , .lg , .ms , .mx , .nd , .nf , .ns , .nv , .oa , .oi
This worm spreads via the Internet as an attachment to infected messages. The attachment does not contain a copy of the worm, but a component which will download the latest version of the worm via the Internet from a variety of sites. The worm is a Windows PE EXE file 101,083 bytes in size. It is packed using UPX. The unpacked file is approximately 376KB in size. InstallationWhen launched, the worm copies its executable file to the Windows directory as “tpup.exe”: %WinDir%\tpup.exeand then launches it with the 's' option. It extracts the following file from its body: %System%\e1.dll.This file is 6144 bytes in size. In order to ensure that its components are loaded the next time Windows is started, the worm creates the following parameters in the system registry: [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]tpup=%WinDir%\tpup.exe s
[HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] Propagation via emailThe worm harvests addresses from the outlook address book and from files on the user's hard disk. Harvested addresses will be saved to a file with the following name: %WinDir%\tpup.wax
PayloadThe worm sends messages which contain a Trojan downloader in the attachment to email addresses harvested from the victim machine. This Trojan downloader will download the worm's main executable file from the Internet. Message subject (chosen at random from the list below):
Message body (chosen at random from the list below):
Attachment name (will contain one of the following strings):
The attachement will have a .zip, a “doc.exe” or a “txt.exe” extension, which will have a large number of spaces in front of it. The worm creates the following files: %WinDir%\tpup.dat%WinDir%\tpup.s The worm component is the following file: %System%\e1.dllThe worm code will be injected into randomly chosen processes on the victim machine. It is designed to disable antivirus protection. The worm component attempts to terminate antivirus and personal firewall processes and to stop their services. The worm also downloads a list of links to files on the Internet. It will then download files from these links, save them to the Windows temporary directory, and launch them.
Urgent updates containing detection for this program have been released. If you are using Kaspersky Anti-Virus 6.0, enable Proactive Protection and the solution will be able to detect and neutralize new variants without the need to update your antivirus databases. If you do not have an up to date antivirus on your computer, and have been infected by this malicious program, you should follow the instructions below:
|
|||||||||||