- Dref:
- Email messages
- Network shares
- Infected files
- Turns off anti-virus applications
- Sends itself to email addresses found on the infected computer
- Drops more malware
- Downloads code from the internet
- Reduces system security
- Installs itself in the Registry
W32/Dref-V sends emails with the following characteristics:
From:
Subject line: "Happy New Year!"
Message text:
Attached file: postcard.exe
From:
"Annual Fun Forecast!" - "Baby New Year !"
- "Best Wishes For A Happy New Year!"
- "Fun 2007!"
- "Fun Filled New Year!"
- "Happiness And Continued Success!"
- "Happiness and Success!"
- "Welcome 2007!"
- "Wish You Smiles And Good Cheer!"
- "Warm New Year Hug!"
Attached file:chosen from
Postcard.exe - Greeting Card.exe
- Greeting Postcard.exe

W32/Dref-V includes functionality to access the internet and communicate with a remote server via HTTP.
When first run W32/Dref-V copies itself to
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Agent
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Agent
W32/Dref-V sets the following registry entries, disabling the automatic startup of other software:
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start
4
Note: disabling autostart for the SharedAccess service deactivates the Microsoft Internet Connection Firewall (ICF).
- Netsky:
The worm copies itself to the Windows folder as FVProtect.exe and adds the following registry entry to run itself whenever the user logs on to the computer:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Norton Antivirus AV
=
The worm will also copy itself to various peer-to-peer shared folders as the following files:
- 1001 Sex and more.rtf.exe
- 3D Studio Max 6 3dsmax.exe
- ACDSee 10.exe
- Adobe Photoshop 10 crack.exe
- Adobe Photoshop 10 full.exe
- Adobe Premiere 10.exe
- Ahead Nero 8.exe
- Altkins Diet.doc.exe
- American Idol.doc.exe
- Arnold Schwarzenegger.jpg.exe
- Best Matrix Screensaver new.scr
- Britney sex xxx.jpg.exe
- Britney Spears and Eminem porn.jpg.exe
- Britney Spears blowjob.jpg.exe
- Clone DVD 6.exe
- Cloning.doc.exe
- Cracks & Warez Archiv.exe
- Dark Angels new.pif
- Dictionary English 2004 - France.doc.exe
- DivX 8.0 final.exe
- Doom 3 release 2.exe
- E-Book Archive2.rtf.exe
- Eminem full album.mp3.exe
- Eminem Song text archive.doc.exe
- Eminem.mp3.exe
- Full album all.mp3.pif
- Gimp 1.8 Full with Key.exe
- Harry Potter 1-6 book.txt.exe
- Harry Potter 5.mpg.exe
- Harry Potter all e.book.doc.exe
- Harry Potter e book.doc.exe
- Harry Potter game.exe
- Harry Potter.doc.exe
- How to hack new.doc.exe
- Internet Explorer 9 setup.exe
- Kazaa Lite 4.0 new.exe
- Kazaa new.exe
- Keygen 4 all new.exe
- Learn Programming 2004.doc.exe
- Lightwave 9 Update.exe
- Magix Video Deluxe 5 beta.exe
- Matrix.mpg.exe
- Microsoft Office 2003 Crack best.exe
- Microsoft WinXP Crack full.exe
- MS Service Pack 6.exe
- netsky source code.scr
- Norton Antivirus 2005 beta.exe
- Opera 11.exe
- Partitionsmagic 10 beta.exe
- Porno Screensaver britney.scr
PL, HTM, HTML, EML, TXT, PHP, ASP, VBS, RTF, UIN, SHTM, CGI, DHTM, ADB, TBB, DBX, SHT, OFT, MSG, JSP, WSH, XML.
The worm has a trigger date of 24 March 2004, at which time it will attempt to mass mail.
Attached filename:
W32/Netsky-P also creates a number of the TMP files in the Windows folder: base64.tmp, zip1.tmp, zip2.tmp, zip3.tmp, zipped.tmp.
The worm will attempt to harvest email addresses from the local hard disk by scanning files with extensions WAB, PL, ADB, TBB, DBX, ASP, PHP, SHTL and HTM.
This worm will test for the presence of an internet connection by attempting to connect to www.google.com or www.microsoft.com.
W32/Zafi-B collects email addresses from files which have the following extensions:
HTM, WAB, TXT, DBX, TBB, ASP, PHP, SHT, ADB, MBX, EML and PMR.
The worm stores the collected email addresses in randomly named files with a
DLL extension in the Windows system folder.
W32/Zafi-B attempts to include itself as an attachment in email messages sent to addresses collected from the local machine. The worm will also copy itself into shared P2P folders as either 'WINAMP 7.0 FULL_INSTALL.EXE' or
'TOTAL COMMANDER 7.0 FULL_INSTALL.EXE'.
W32/Zafi-B may display a message box on screen containing the following Hungarian text:
Below are examples of the emails sent by W32/Zafi-B.
Subject: Ingyen SMS!
Message:
------------------------ hirdet=E9s -----------------------------
A sikeres 777sms.hu =E9s az axelero.hu t=E1mogat=E1s=E1val =FAjra
indul az ingyenes sms k=FCld=F5 szolg=E1ltat=E1s! Jelenleg ugyan
korl=E1tozott sz=E1mban, napi 20 ingyen smst lehet felhaszn=E1lni.
K=FCldj te is SMST! Neh=E1ny kattint=E1s =E9s a mell=E9kelt regisztr=E1ci=F3s lap kit=F6lt=E9se ut=E1n azonnal ig=E9nybevehet=F5! B=F5vebb inform=E1ci=F3t a www.777sms.hu oldalon tal=E1lsz, de siess,
mert az els=F5 ezer felhaszn=E1l=F3 k=F6z=F6tt =E9rt=E9kes nyerem=E9nyeket sorsolunk ki!
------------------------ axelero.hu ---------------------------
Subject: You`ve got 1 VoiceMessage!
Message: Dear Customer!
You`ve got 1 VoiceMessage from voicemessage.com website!
Sender:
You can listen your Virtual VoiceMessage at the following link:
http://virt.voicemessage.com/index.listen.php2=35affv
or by clicking the attached link.
Send VoiceMessage! Try our new virtual VoiceMessage Empire!
Best regards: SNAF.Team (R).
Subject: Check this out kid!!!
Message: Send me back bro, when you`ll be done...(if you know what i mean...)
See ya,
W32/MyDoom-O creates a file named services.exe in the Windows or Temp folder and runs the file. Services.exe is a backdoor component.
W32/MyDoom-O searches the hard disk email addresses. The worm searches files with the extensions PL*, PH*, TX*, HT*, ASP, TBB, SHT*, WAB, ADB and DBX and the Windows address book. In addition the worm may use an internet search engine to find more email addresses. The worm will send a query to the search engine using domain names from email addresses found on the hard disk and then examine the query results, searching for more addresses. The internet search engines used by W32/MyDoom-O and the percentage chance that each is used are:
--Dear user of
Mail server administrator of would like to inform you that We have detected that your e-mail account has been used to send a large amount of unsolicited e-mail messages during this recent week. We suspect that your computer had been compromised by a recent virus and now runs a trojan proxy server. Please follow our instructions in the attachment file in order to keep your computer safe. Virtually yours
user support team.--
W32/Sality-AA creates the file\vcmgcd32.dll. This file is also detected as W32/Sality-AA.
The virus logs keystrokes to certain windows, as well as information about the infected computer. This logged data is periodically submitted to a remote website.
W32/Nyxem-D may open an empty dropped ZIP file in order to hide its functionality.
W32/Nyxem-D may periodically attempt to download and run an update of itself.
W32/Nyxem-D may attempt to display an icon in the Windows taskbar with the text "Update Please wait" if it detects the presence of anti-virus software. W32/Nyxem-D may also attempt to close windows, terminate programs, remove registry entries and delete files related to security and anti-virus programs.
W32/Nyxem-D sends itself to email addresses it harvests from files on the infected computer, sending itself as if from one contact to another.Message bodies may contain images that cannot be displayed:
W32/Nyxem-D attempts to spread to network shares with weak passwords.
When run Troj/StraDl-B attempts to download a file from a remote website and run it. This file is currently detected as W32/Strati-Gen.
- Attachment: No Virus found
- MessageLabs AntiVirus - www.messagelabs.com
- Attachment: No Virus found
- Bitdefender AntiVirus - www.bitdefender.com
- Attachment: No Virus found
- MC-Afee AntiVirus - www.mcafee.com
- Attachment: No Virus found
- Kaspersky AntiVirus - www.kaspersky.com
- Attachment: No Virus found
- Panda AntiVirus - www.pandasoftware.com
W32/Netsky-P also creates a number of the TMP files in the Windows folder: base64.tmp, zip1.tmp, zip2.tmp, zip3.tmp, zipped.tmp.
- Mytob:
- Allows others to access the computer
- Sends itself to email addresses found on the infected computer
- Forges the sender's email address
- Uses its own emailing engine
The worm will attempt to harvest email addresses from the local hard disk by scanning files with extensions WAB, PL, ADB, TBB, DBX, ASP, PHP, SHTL and HTM.
- Stratio:
- Bagle:
- Zafi:
- I-Worm.Zafi.b
- W32/Zafi.b@MM
- Win32/Zafi.B
- W32.Erkez.B@mm
- PE_ZAFI.B
This worm will test for the presence of an internet connection by attempting to connect to www.google.com or www.microsoft.com.
W32/Zafi-B collects email addresses from files which have the following extensions:
HTM, WAB, TXT, DBX, TBB, ASP, PHP, SHT, ADB, MBX, EML and PMR.
The worm stores the collected email addresses in randomly named files with a
DLL extension in the Windows system folder.
W32/Zafi-B attempts to include itself as an attachment in email messages sent to addresses collected from the local machine. The worm will also copy itself into shared P2P folders as either 'WINAMP 7.0 FULL_INSTALL.EXE' or
'TOTAL COMMANDER 7.0 FULL_INSTALL.EXE'.
W32/Zafi-B may display a message box on screen containing the following Hungarian text:
Below are examples of the emails sent by W32/Zafi-B.
Subject: Ingyen SMS!
Message:
------------------------ hirdet=E9s -----------------------------
A sikeres 777sms.hu =E9s az axelero.hu t=E1mogat=E1s=E1val =FAjra
indul az ingyenes sms k=FCld=F5 szolg=E1ltat=E1s! Jelenleg ugyan
korl=E1tozott sz=E1mban, napi 20 ingyen smst lehet felhaszn=E1lni.
K=FCldj te is SMST! Neh=E1ny kattint=E1s =E9s a mell=E9kelt regisztr=E1ci=F3s lap kit=F6lt=E9se ut=E1n azonnal ig=E9nybevehet=F5! B=F5vebb inform=E1ci=F3t a www.777sms.hu oldalon tal=E1lsz, de siess,
mert az els=F5 ezer felhaszn=E1l=F3 k=F6z=F6tt =E9rt=E9kes nyerem=E9nyeket sorsolunk ki!
------------------------ axelero.hu ---------------------------
Subject: You`ve got 1 VoiceMessage!
Message: Dear Customer!
You`ve got 1 VoiceMessage from voicemessage.com website!
Sender:
You can listen your Virtual VoiceMessage at the following link:
http://virt.voicemessage.com/index.listen.php2=35affv
or by clicking the attached link.
Send VoiceMessage! Try our new virtual VoiceMessage Empire!
Best regards: SNAF.Team (R).
Subject: Check this out kid!!!
Message: Send me back bro, when you`ll be done...(if you know what i mean...)
See ya,
- Mydoom:
W32/MyDoom-O creates a file named services.exe in the Windows or Temp folder and runs the file. Services.exe is a backdoor component.
W32/MyDoom-O searches the hard disk email addresses. The worm searches files with the extensions PL*, PH*, TX*, HT*, ASP, TBB, SHT*, WAB, ADB and DBX and the Windows address book. In addition the worm may use an internet search engine to find more email addresses. The worm will send a query to the search engine using domain names from email addresses found on the hard disk and then examine the query results, searching for more addresses. The internet search engines used by W32/MyDoom-O and the percentage chance that each is used are:
- www.google.com (45%)
- search.lycos.com (22.5%)
- search.yahoo.com (20%)
- www.altavista.com (12.5%)
--Dear user of
Mail server administrator of
- Sality:
- Records keystrokes
- Virus.Win32.Sality.q
- W32/Sality.x
- Win32/Sality.NAJ
- PE_SALITY.AS
W32/Sality-AA creates the file
The virus logs keystrokes to certain windows, as well as information about the infected computer. This logged data is periodically submitted to a remote website.
- Nyxem:
- Turns off anti-virus applications
- Sends itself to email addresses found on the infected computer
- Deletes files off the computer
- Forges the sender's email address
- Uses its own emailing engine
- Downloads code from the internet
- Reduces system security
- Installs itself in the Registry
- Email-Worm.Win32.VB.bi
- CME-24
- WORM_GREW.A
- W32.Blackmal.E@mm
- W32/Tearec.A.worm
- Email-Worm.Win32.Nyxem.e
- W32/MyWife.d@MM
- Win32/Mywife.E@mm
- WORM_NYXEM.E
W32/Nyxem-D may open an empty dropped ZIP file in order to hide its functionality.
W32/Nyxem-D may periodically attempt to download and run an update of itself.
W32/Nyxem-D may attempt to display an icon in the Windows taskbar with the text "Update Please wait" if it detects the presence of anti-virus software. W32/Nyxem-D may also attempt to close windows, terminate programs, remove registry entries and delete files related to security and anti-virus programs.
W32/Nyxem-D sends itself to email addresses it harvests from files on the infected computer, sending itself as if from one contact to another.Message bodies may contain images that cannot be displayed:
W32/Nyxem-D attempts to spread to network shares with weak passwords.
- Stardl:
- Downloads code from the internet
When run Troj/StraDl-B attempts to download a file from a remote website and run it. This file is currently detected as W32/Strati-Gen.


0 comments:
Post a Comment