|
Top 10 malware reported to Sophos in 2002
Note: W32/Klez-H is capable of spreading using a forged Sophos
email address. Of course, Sophos has not sent these emails and has not been
infected by this worm. You can read more about this
here.
W32/Klez-H is detected by Sophos Anti-Virus version 3.55 and later as
W32/Klez-G
using a generic detection technique.
W32/Klez-H is a Win32 worm that carries a compressed copy of the
W32/ElKern-C
virus which it drops into the Program Files directory and executes.
W32/Klez-H copies itself into the Windows system directory with a random
filename. The filename begins with the characters "wink" and has the
extension EXE.
The worm searches for email addresses in the Windows address book and
also in files with the extensions TXT, HTM, HTML, WAB, ASP, DOC, RTF, XLS,
JPG, CPP, C, PAS, MPG, MPEG, BAK, MP3 and PDF.
The email message "From:" field will contain either one of the addresses
found in the search or an address taken from a list inside the virus body.
The worm sends itself using emails with the following characteristics:
Subject line:
The subject line is randomly created using one of the following rules.
1.
A combination of "Hi,", "Hello," "Re:", "Fw:", or nothing
with
"Very", "special", "Happy" or "Have a" as the first part of the sentence
and
"New", "funny", "nice", "humour", "excite", "good", "powful", "WinXP",
"IE 6.0" or nothing as the second, arranged in one of the following
sentences:
"A %s %s game."
"A %s %s tool."
"A %s %s website."
"A %s %s patch."
"%s %s Allhallowmas"
"%s %s Epiphany"
e.g. "A special powful tool" or "Happy Allhallowmas"
2.
A combination of "W32.Elkern" or "W32.Klez.E" and "removal tools".
e.g. "W32.Klez.E removal tools"
3.
One chosen from the following list:
how are you
let's be friends
darling
so cool a flash,enjoy it
your password
honey
some questions
please try again
welcome to my hometown
the Garden of Eden
introduction on ADSL
meeting notice
questionnaire
congratulations
Sos!
japanese girl VS playboy
look,my beautiful girl friend
eager to see you
spice girls' vocal concert
japanese lass' sexy pictures
Undeliverable mail --
Returned mail --
4.
Worm Klez.E immunity
Message text:
The message text is randomly composed by the worm, and may be left blank.
If the subject line is "Worm Klez.E immunity", then the message text is
"Klez.E is the most common world-wide spreading worm. It's very dangerous by
corrupting your files. Because of its very smart stealth and anti-anti-virus
technic,most common AV software can't detect or clean it. We developed this
free immunity tool to defeat the malicious virus. You only need to run this
tool once,and then Klez will never come into your PC. NOTE:
Because this tool acts as a fake Klez to fool the real worm,some AV monitor
maybe cry when you run it. If so,Ignore the warning,and select 'continue'.
If you have any question,please mail to me."
Attached file:
Randomly named with the extension PIF, SCR, EXE or BAT.
Because the worm uses its own SMTP engine, the message may appear to come
from any email address. Some of the messages will have a "From:" field and
message text which imply that the message was sent by a major anti-virus
vendor (namely Kaspersky, F-Secure, Sophos, Symantec and Trend Micro).
The SMTP server used to send the messages is taken from the value "SMTP
Server" of the registry key
HKCU\Software\Microsoft\Internet Account\Manager\Accounts
When sending email, W32/Klez-H may attach a randomly chosen file from the
infected computer with the extension TXT, HTM, HTML, WAB, ASP, DOC, RTF, XLS,
JPG, CPP, C, PAS, MPG, MPEG, BAK, MP3, or PDF. This means that the worm may
cause the disclosure of confidential company data.
W32/Klez-H attempts to disable several anti-virus software products and to
delete some anti-virus related files.
The worm attempts to exploit a MIME and an IFRAME vulnerability in some
versions of Microsoft Outlook, Microsoft Outlook Express, and Internet
Explorer to allow the executable file to run automatically without the user
double-clicking on the attachment. Microsoft has issued a patch which
secures against this vulnerability which can be downloaded from
Microsoft Security Bulletin MS01-027. (This patch was released to fix a
number of vulnerabilities in Microsoft's software, including the one
exploited by this worm.)
W32/Klez-H may also spread to remote shares on other machines using random
filenames. The dropped files may have a double extension formed by using a
combination of extensions randomly taken from the two lists. The first
extension is taken from the following list:
TXT
HTM
HTML
WAB
ASP
DOC
RTF
XLS
JPG
CPP
C
PAS
MPG
MPEG
BAK
MP3
PDF
The second extension is taken from:
PIF
SCR
EXE
BAT
For example, the double extension may be .txt.exe.
W32/Klez-H will add a value "wink<random>" to registry run command, so that
the dropped file will run on Windows startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Additionally the worm will attempt to disable anti-virus software by
stopping any of the following processes,
_AVP32
_AVPCC
NOD32
NPSSVC
NRESQ32
NSCHED32
NSCHEDNT
NSPLUGIN
NAV
NAVAPSVC
NAVAPW32
NAVLU32
NAVRUNR
NAVW32
_AVPM
ALERTSVC
AMON
AVP32
AVPCC
AVPM
N32SCANW
NAVWNT
ANTIVIR
AVPUPD
AVGCTRL
AVWIN95
SCAN32
VSHWIN32
F-STOPW
F-PROT95
ACKWIN32
VETTRAY
VET95
SWEEP95
PCCWIN98
IOMON98
AVPTC
AVE32
AVCONSOL
FP-WIN
DVP95
F-AGNT95
CLAW95
NVC95
SCAN
VIRUS
LOCKDOWN2000
Norton
Mcafee
Antivir
TASKMGR
and deleting the files
ANTI-VIR.DAT
CHKLIST.DAT
CHKLIST.MS
CHKLIST.CPS
CHKLIST.TAV
IVB.NTZ
SMART CHK.MS
SMARTCHK.CPS
AVGQT.DAT
AGUARD.DAT
|
|
|
This web is optimized for 800 x 600 monitor resolution or above and
the latest web browser. Get the latest IE or Netscape web browser. (you
need to connect to the internet first) |
|