Virus Characteristics
The 4192 DAT files (or higher) and 4.1.60+ scan engine will detect this threat in some environments. The detected name is
Exploit-Codebase
.
This malware bears similarities to Downloader-CY
in message construction, which was spammed several days ago. This threat may have also been spammed. It is received as an email attachment as follows.
From:
Admin (ADMIN@
your_domain
)
Subject:
your account
%user%
Importance:
High
Hello there,
I would like to inform you about important information regarding your email address. This email address will be expiring. Please read attachment for details.
--- Best regards, Administrator
Attachment:
message.zip
The attached .ZIP file contains a file named MESSAGE.HTM. This file uses the codebase exploit (MS02-015
) and MHTML exploit (MS03-014
) to automatically create the file foo.exe
in the Temporary Internet Files folder and run it.
Note:
The MS03-014 patch must be applied to prevent the automatic execution of the executable when accessing the MESSAGE.HTM file.
The following files are created in the WINDOWS (%WinDir%) directory:
- videodrv.exe (19,824 bytes)
- exe.tmp (20,445 bytes)
- zip.tmp (20,567 bytes)
The following registry run key is created to load the worm at startup:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "VideoDriver" = C:\WINNT\videodrv.exe
First, the virus checks to see if the system is connected to the Internet by trying to contact google.com. If this check succeeds, the virus attempts to harvest email addresses from the local system. It grabs addresses from all files on the system, except files that have the following extensions:
- avi
- bmp
- cab
- com
- dll
- exe
- gif
- jpg
- mp3
- mpg
- ocx
- pdf
- psd
- rar
- tif
- vxd
- wav
- zip
Found addresses are stored in a file named
eml.tmp
in the WINDOWS directory.
An additional registry key is created:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
Code Store Database\Distribution Units\
{11111111-1111-1111-1111-111111111111}