0 0
This worm spreads via MSN by means of file transfer. The worm file is packed using several packing programs, and is approximately 17KB when packed. The unpacked file is approximately 155KB in size.
InstallationThe worm copies itself to the Windows directory under one of the following names:
formatsys.exe lspt.exe msmbw.exe serbw.exe
The copied file will be assigned a "hidden" attribute, making it invisible to the majority of users.
The worm then registers itself in the system registry under one of the following names:
avnort serpe ltwob
in the following locations:
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run]
It changes the %WINDIR%\System32\Drivers\etc\hosts file to block access to the sites of antivirus companies from the infected computer:
64.233.167.104 avp.com 64.233.167.104 ca.com 64.233.167.104 customer.symantec.com 64.233.167.104 dispatch.mcafee.com 64.233.167.104 download.mcafee.com 64.233.167.104 f-secure.com 64.233.167.104 grisoft.com 64.233.167.104 kaspersky.com 64.233.167.104 kaspersky-labs.com 64.233.167.104 liveupdate.symantec.com 64.233.167.104 liveupdate.symantecliveupdate.com 64.233.167.104 mast.mcafee.com 64.233.167.104 mcafee.com 64.233.167.104 my-etrust.com 64.233.167.104 nai.com 64.233.167.104 networkassociates.com 64.233.167.104 rads.mcafee.com 64.233.167.104 sandbox.norman.no 64.233.167.104 secure.nai.com 64.233.167.104 securityresponse.symantec.com 64.233.167.104 sophos.com 64.233.167.104 symantec.com 64.233.167.104 trendmicro.com 64.233.167.104 uk.trendmicro-europe.com 64.233.167.104 update.symantec.com 64.233.167.104 updates.symantec.com 64.233.167.104 us.mcafee.com 64.233.167.104 viruslist.com 64.233.167.104 www.avp.com 64.233.167.104 www.ca.com 64.233.167.104 www.f-secure.com 64.233.167.104 www.grisoft.com 64.233.167.104 www.kaspersky.com 64.233.167.104 www.mcafee.com 64.233.167.104 www.my-etrust.com 64.233.167.104 www.nai.com 64.233.167.104 www.networkassociates.com 64.233.167.104 www.pandasoftware.com 64.233.167.104 www.sophos.com 64.233.167.104 www.trendmicro.com 64.233.167.104 www.viruslist.com 64.233.167.104 www.symantec.com
When spreading, it uses one of the following names to encourage users to accept the file transfer and launch the worm:
- Annoying crazy frog getting killed.pif
- Crazy frog gets killed by train!.pif
- Fat Elvis! lol.pif
- How a Blonde Eats a Banana...pif
- Jennifer Lopez.scr
- LOL that ur pic!.pif
- Me on holiday!.pif
- Mona Lisa Wants Her Smile Back.pif
- My new photo!.pif
- See my lesbian friends.pif
- The Cat And The Fan piccy.pif
- Topless in Mini Skirt! lol.pif
- lspt.exe
The worm creates files with the following names in the system disk root directory.
- Annoying crazy frog getting killed.pif Crazy frog gets killed by train!.pif
- Fat Elvis! lol.pif
- How a Blonde Eats a Banana...pif
- Jennifer Lopez.scr
- LOL that ur pic!.pif
- Me on holiday!.pif
- Mona Lisa Wants Her Smile Back.pif
- My new photo!.pif
- See my lesbian friends.pif
- The Cat And The Fan piccy.pif
- Topless in Mini Skirt! lol.pif
- lspt.exe
All the files will be ascribed the "hidden" attribute.
The worm kills the following processes:
avengine.exe apvxdwin.exe atupdater.exe aupdate.exe autodown.exe autotrace.exe autoupdate.exe avconsol.exe avsynmgr.exe avwupd32.exe avxquar.exe bawindo.exe blackd.exe ccapp.exe ccevtmgr.exe ccproxy.exe ccpxysvc.exe cfiaudit.exe defwatch.exe drwebupw.exe escanh95.exe escanhnt.exe nisum.exe firewall.exe frameworkservice.exe icssuppnt.exe icsupp95.exe luall.exe lucoms~1.exe mcagent.exe mcshield.exe mcupdate.exe mcvsescn.exe mcvsrte.exe mcvsshld.exe navapsvc.exe navapw32.exe nopdb.exe nprotect.exe nupgrade.exe outpost.exe pavfires.exe pavproxy.exe pavsrv50.exe rtvscan.exe rulaunch.exe savscan.exe shstat.exe sndsrvc.exe symlcsvc.exe Update.exe updaterui.exe vshwin32.exe vsstat.exe vstskmgr.exe cmd.exe msconfig.exe msdev.exe ollydbg.exe peid.exe petools.exe regedit.exe reshacker.exe taskmgr.exe w32dasm.exe winhex.exe wscript.exe
The worm contains the following text:
'-F-u-c-k-'-Y-o-u-' Hey LARISSA fuck off, you fucking n00b!.. Bla bla to your fucking Saving the world from Bropia, the world n33ds saving from you! '-S-K-Y-'-D-E-V-I-L-' .:*Fuck-Off*:.

Subscribe
Hot Articles