Win32.Auric.A@mm( I-Worm.Magold.a (Kaspersky), WORM_AURIC.A (Trend Micro), )
SYMPTOMS: \"=:-) OFFSPRING is co0L =:-) PUNK\'S NOT DEAD =:-)\" TECHNICAL DESCRIPTION: victim\'s hard drive. From: EROTIKA.LAP.HU Subject: Maya Gold-os kepernyokimelo! Attachment: \"Maya Gold.scr\" Body: Tisztelt cim! Az EROTIKA.LAP.HU nezettsegenek novelese erdekeben egy kis izelitot kivan adni kinalatabol az Internet felhasznaloknak! FIGYELEM: A \'Maya Gold.scr\' nevu csatolt allomany egy kepernyovedo. Mint a neve is mutatja Maya Gold pornoszinesznorol tartalmaz kulonbozo kepeket. Az allomanyt ajanlott elobb a lemezre menteni, majd utana futtatni. Amennyiben valami problemaja, kerdese van, irjon a kovetkezo cimre: erotika@lap.hu Udvozlettel: EROTIKA.LAP.HU After sending messages to all recipients, the worm sends another mail that contains information about victim\'s computer, to the virus coder: From: EROTIKA.LAP.HU To: rave-punk@freemail.hu Subject: Maya Gold-os kepernyokimelo! Body: Szevasz haver! Ez tokre bejott! Nesze a cucc: Nev: Winver: Felkesz: Megoszt: PUNKS NOT DEAD \"=:-) OFFSPRING is co0L =:-) PUNK\'S NOT DEAD =:-)\" Key: \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\" Subkey: \"raVe\" Value: \"C:\\%WINDIR%\\raVe.exe\" Key: \"HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\RunServices\" Subkey: \"raVe\" Value: \"C:\\%WINDIR%\\raVe.exe\" Additional registry entries are created to keep track of virus activity: Key: \"HKEY_LOCAL_MACHINE\\Software\\raVe\" Subkeys: \".exe\", \".scr\", \".com\", \".bat\", \".pif\". LimeWire, Gnucleus, Shareaza, BearShare, Edonkey2000, Morpheus, Grokster, ICQ/Shared Files, Kazaa. Removal instructions: Key: HKEY_LOCAL_MACHINE\\Software\\Classes\\exefile\\shell\\open\\command Value: Replace with: %1 %* Key: HKEY_CLASSES_ROOT\\exefile\\shell\\open\\command Value: Replace with: %1 %* * Kills the worm processes * Deletes the worm files that would run at startup * Corrects the executable file associations * Restores the windows colors to normal * Deletes the empty RAVE???? text files from desktop * Deletes the HKEY_LOCAL_MACHINE\\Software\\raVe keys * Deletes the %SystemDir%\\ravec.txt file * If all fixed drives are scanned, all the worm files, autorun.inf from mapped drives and infected IRC scripts are deleted ANALYZED BY: Mihai NeaguBitDefender Virus Researcher |