Virus Characteristics
This threat is detected as VBS/Zync. When the infected VBScript is executed, the virus will copy itself as the following:
- [windows SYSTEM directory]\Ddhelp.dll.vbs
- [windows directory]\Win32.dll.vbs
- [windows directory]\Application Data\Microsoft\Internet Explorer\
Quick Launch\Silent Night.vbs
The virus will create the file c:\Backup.bat, which will display the message
Silent Nights, Lonely Nights.. This file is detected as VBS/Zync.
The following registry keys will be added:
- HKCU\Control Panel\Desktop\ScreenSaveUsePassword, 1, "REG_DWORD"
- HKCU\Control Panel\Desktop\ScreenSaveTimeOut, 9999
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Gue§§ CreW\, ""
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Gue§§ CreW\DisplayName, "NightLife"
- HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Gue§§ CreW\UninstallString, dirw1&"\nLifeUninstall.dll"
On the 1, 5, 10, 13, 15, 20 or 25th day of any month, the following registry keys will be added:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Version, "Silent Nights 2001"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
RegisteredOwner, "(iN)Zync"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
RegisteredOrganization, "GueSS CreW"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
URL\DefaultPrefix, "GueSSCreW://"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
URL\Prefixes\ftp", "GueSSCreWFTP://"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
URL\Prefixes\www", "GueSSCreW://"
On the 13th day of any month, the following registry keys will be added:
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Version, "£0®Ð4ÑG3® 2001"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
RegisteredOwner, "£0®Ð4ÑG3®^Gûê§§"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
RegisteredOrganization, "Gue§§ CreW"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
ProductKey, "043"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
ProductId, "NightLife is the only life i know"
- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
ProductName, "Windows 256 - GueSS Edition"
The following message will be displayed: