Win32.Auric.A@mm( I-Worm.Magold.a (Kaspersky), WORM_AURIC.A (Trend Micro), )
SYMPTOMS: "=:-) OFFSPRING is co0L =:-) PUNK\'S NOT DEAD =:-)" TECHNICAL DESCRIPTION: victim's hard drive. From: EROTIKA.LAP.HU Subject: Maya Gold-os kepernyokimelo! Attachment: "Maya Gold.scr" Body: Tisztelt cim! Az EROTIKA.LAP.HU nezettsegenek novelese erdekeben egy kis izelitot kivan adni kinalatabol az Internet felhasznaloknak! FIGYELEM: A 'Maya Gold.scr' nevu csatolt allomany egy kepernyovedo. Mint a neve is mutatja Maya Gold pornoszinesznorol tartalmaz kulonbozo kepeket. Az allomanyt ajanlott elobb a lemezre menteni, majd utana futtatni. Amennyiben valami problemaja, kerdese van, irjon a kovetkezo cimre: erotika@lap.hu Udvozlettel: EROTIKA.LAP.HU After sending messages to all recipients, the worm sends another mail that contains information about victim's computer, to the virus coder: From: EROTIKA.LAP.HU To: rave-punk@freemail.hu Subject: Maya Gold-os kepernyokimelo! Body: Szevasz haver! Ez tokre bejott! Nesze a cucc: Nev: Winver: Felkesz: Megoszt: PUNKS NOT DEAD "=:-) OFFSPRING is co0L =:-) PUNK\'S NOT DEAD =:-)" Key: "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run" Subkey: "raVe" Value: "C:\%WINDIR%\raVe.exe" Key: "HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices" Subkey: "raVe" Value:\"C:\%WINDIR%\raVe.exe" Additional registry entries are created to keep track of virus activity: Key:\"HKEY_LOCAL_MACHINE\Software\raVe" Subkeys: ".exe", ".scr", ".com", ".bat", ".pif". LimeWire, Gnucleus, Shareaza, BearShare, Edonkey2000, Morpheus, Grokster, ICQ/Shared Files, Kazaa. Removal instructions: Key: HKEY_LOCAL_MACHINE\Software\Classes\exefile\shell\open\command Value: Replace with: %1 %* Key: HKEY_CLASSES_ROOT\exefile\shell\open\command Value: Replace with: %1 %* * Kills the worm processes * Deletes the worm files that would run at startup * Corrects the executable file associations * Restores the windows colors to normal * Deletes the empty RAVE???? text files from desktop * Deletes the HKEY_LOCAL_MACHINE\Software\raVe keys * Deletes the %SystemDir%\ravec.txt file * If all fixed drives are scanned, all the worm files, autorun.inf from mapped drives and infected IRC scripts are deleted ANALYZED BY: Mihai Neagu BitDefender Virus Researcher |