This detection is for a
mass-mailing worm that combines
W32/Mydoom@MM functionality with
W32/Sdbot.worm functionality.
Mail Propagation
The virus arrives in an email
message as follows:
From:
(Spoofed email sender -
may choose from the following
list)
Do not assume that the apparent
sender address is an indication
that the sender is infected.
Additionally you may receive
alert messages from a mail
server saying that you are
infected, which may not be the
case.
-
support
-
administrator
-
mail
-
service
-
admin
-
info
-
register
-
webmaster
Subject:
(Varies, such as)
- Your password has been
updated
- Your password has been
successfully updated
- You have successfully
updated your password
- Your new account
password is approved
- Your Account is
Suspended
- *DETECTED* Online User
Violation
- Your Account is
Suspended For Security
Reasons
- Warning Message: Your
services near to be closed.
- Important Notification
- Members Support
- Security measures
- Email Account Suspension
- Notice of account
limitation
Body:
(Varies, such as)
- Dear user
(name in To:
address) ,
You have successfully
updated the password of
your (first part of
recipient domain name)
account.
If you did not authorize
this change or if you need
assistance with your
account, please contact
(first part of recipient
domain name) customer
service at: (From:
address)
Thank you for using
(first part of recipient
domain name) !
The (first part of
recipient domain name)
Support Team
+++ Attachment: No Virus
(Clean)
+++ (first part of
recipient domain name)
Antivirus - www.(Full
domain name)
- Dear user
(name in To:
address) ,
It has come to our attention
that your (first part of
recipient domain name)
User Profile ( x ) records
are out of date. For further
details see the attached
document.
Thank you for using
(first part of recipient
domain name) !
The (first part of
recipient domain name)
Support Team
+++ Attachment: No Virus
(Clean)
+++ (first part of
recipient domain name)
Antivirus - www.(Full
domain name)
- Dear
(first part of recipient
domain name)
Member,
We have temporarily
suspended your email account
(To: address) .
This might be due to either
of the following reasons:
1. A recent change in your
personal information (i.e.
change of address).
2. Submiting invalid
information during the
initial sign up process.
3. An innability to
accurately verify your
selected option of
subscription due to an
internal error within our
processors.
See the details to
reactivate your (first
part of recipient domain
name) account.
Sincerely,The (first
part of recipient domain
name) Support Team
+++ Attachment: No Virus
(Clean)
+++ (first part of
recipient domain name)
Antivirus - www.(Full
domain name)
- Dear
(first part of recipient
domain name)
Member,
Your e-mail account was used
to send a huge amount of
unsolicited spam messages
during the recent week. If
you could please take 5-10
minutes out of your online
experience and confirm the
attached document so you
will not run into any future
problems with the online
service.
If you choose to ignore our
request, you leave us no
choice but to cancel your
membership.
Virtually yours,
The (first part of
recipient domain name)
Support Team
+++ Attachment: No Virus
found
+++ (first part of
recipient domain name)
Antivirus - www.(Full
domain name)
Attachment:
(Varies - chooses from the
following list of prefaces)
- updated-password
- email-password
- new-password
- password
- approved-password
- account-password
- accepted-password
- important-details
- account-details
- email-details
- account-info
- document
- readme
- account-report
The attachment name may
have one or two file extensions,
in which case multiple spaces
may be inserted as well, for
example:
- document.htm (many
spaces) .pif
Extensions:
(Varies, chooses from the
following list)
First extension:
Final extension:
The file may also arrive in
a ZIP archive.
Installation
When the attachment is run,
the virus copies itself to the
Windows System directory
(e.g. C:\Windows\System32\ on
Windows XP) as winxpserv.exe.
The Hosts file (typically found
in
C:\Windows\System32\Drivers\etc\)
is also appended to direct
several security websites to the
local host, so they cannot be
accessed.This file is detected
and cleaned as Qhosts.apd.
Registry keys are created to
load the worm at startup:
-
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\Run "WINDOWS
SYSTEM" = winxpserv.exe
-
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\
CurrentVersion\RunServices
"WINDOWS SYSTEM"
= winxpserv.exe
The worm attempts to modify
the following registry keys to
lower the "Internet" zone in the
Internet Explorer security
settings:
-
HKEY_CURRENT_USER\Software\Microsoft\Windows\
CurrentVersion\Internet
Settings\Zones\3
- 1001
- 1004
- 1200
- 1201
- 1206
- 1400
- 1402
- 1405
- 1406
- 1407
- 1601
- 1604
- 1605
- 1606
- 1607
- 1608
- 1609
- 1800
- 1802
- 1803
- 1804
- 1805
- 1A00
- 1A02
- 1A03
- 1A04
- 1A05
- 1A06
- 1A10
- 2001
- 2004
This was not observed to
function in testing.
The following registry entry
is also changed to augment the
settings for the Windows XP
Firewall:
-
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SharedAccess