Virus:Worm/Scano.Y
Date discovered:09/05/2006
Type:Worm
In the wild:No
Reported Infections:Low
Distribution Potential:Medium to high
Damage Potential:Medium
Static file:Yes
File size:20.856 Bytes
MD5 checksum:76cb18a39eca764303c4c8c4afabc139
VDF version:6.34.01.56

 General Methods of propagation:
   • Email
   • Peer to Peer


Aliases:
   •  Symantec: W32.Areses.A@mm
   •  Mcafee: W32/Areses.j@MM
   •  TrendMicro: WORM_ARESES.V
   •  Bitdefender: Win32.Scano.Y@mm


Platforms / OS:
   • Windows 2000
   • Windows XP
   • Windows 2003


Side effects:
   • Uses its own Email engine
   • Registry modification
   • Steals information
   • Third party control

 Files It copies itself to the following location:
   • %WINDIR%\csrss.exe



It copies itself within an archive to the following location:
   • %TEMPDIR%\Message.zip




It tries to execute the following files:

– Filename:
   • svchost.exe
using the following command line arguments: %WINDIR%\csrss.exe


– Filename:
   • services.exe
using the following command line arguments: %WINDIR%\csrss.exe

 Registry The following registry key is added in order to run the process after reboot:

– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\
   Image File Execution Options\explorer.exe]
   • Debugger = %WINDIR%\csrss.exe



The values of the following registry key are removed:

–  [HKLM\SYSTEM\ControlSet002\Control\Session Manager]
   • PendingFileRenameOperations
   • BootExecute

 Email It contains an integrated SMTP engine in order to send emails. A direct connection with the destination server will be established. The characteristics are described in the following:


From:
The sender address is spoofed.


To:
– Email addresses found in specific files on the system.


Subject:
One of the following:
   • One of the following:
   • Hi, what's up?
   • He, where are you?
   • Hi, drop me a line!!!
   • Hi! Please write to me urgently!
   • Hi! I'm waiting you online today!
   • Will you be online today?
   • When you're gonna answer me?
   • Re: write to me!
   • Re: Call me!
   • Re: Where are you?
   • Re: When you're gonna answer me?
   • Hi!!! How's the mood?
   • Re: How's the mood?
   • Re: Where have you been?



Body:
The body of the email is one of the following:

   • Hi!!!!! You haven't been writing for a long time. I began to worry) Where have you been? You remember, you've asked a progy from me? I've finally found it, so here it is. Check it out if this is what you've been looking for... bye

   • Hi, what's up? Will you show up online today?
     Drop me a line in ICQ, ok? Btw, I'm sending you the docs you've been looking for, find them attached. Check them out, ok?

   • Hi!
     I'm coming to you tomorrow, ok? When you are going to be home?
     You remember, you've asked some docs. Please find them attached. Check and see what's inside. That's it. Bye, till tomorrow...

   • Hi!
     You disappeared again. If you come online, drop me a line, ok?
     Btw, I sent you those docs that you've been looking for. Check them out. Bye!

   • Hi, give me a call just when you got the message! I'm tired of waiting. Btw, I'm sending that program that you've been looking for. Check it out. Appears to be that one. Bye!

   • Hi, what's up? If you have time tomorrow, please come over. After midday. By the way, don't forget to check the enclosed documents. Bye. See you tomorrow.

   • Hi, I got a free day tomorrow, and I'm waiting for you. Please come after midday. By the way, I'm sending you the documents that you've been asking for. Read them out... Bye!

   • Hi, how are you? What are your plans today? If you have time, please come over, and don't forget to check the program attached. Bye!

   • Hi, what's you gonna do today? I'll come over tonight! By the way, don't give anyone this funny program I'm sending. Check it out. Bye!

   • Hi, I found that program you asked for. Find it attached. Bye.

   • Hi, I saw you around today, but you didn't noticed me ( If you're gonna be at home, give a call, ok? By the way, check this file I'm sending. A very interesting program...

   • What's up! You haven't been writing for a long time
     I got news. I've finally that program you needed
     I'm sending it out. Use it. Bye!

   • Hi, drop me a line today, ok? And see the program I'm sending. Bye!

   • Hi, drop me a line if you can. Btw, I have a new ICQ. Please don't forget to check the attached documents. Bye.

   • Hi! How are you? Drop me a line if you can. I found your documents and I'm emailing them to you. Bye.


Attachment:
The filename of the attachment is constructed out of the following:

–  It starts with one of the following:
   • Message
   • File
   • Document
   • README
   • Passwords
   • Readme
   • Important
   • New
   • COOL
   • Archive
   • Fotos
   • private
   • confidential
   • secret
   • images
   • your_documents
   • backup

    The file extension is one of the following:
   • .exe
   • .zip

 Mailing Search addresses:
It searches the following files for email addresses:
   • .adb; .asp; .cfg; .cgi; .mra; .dbx; .dhtm; .eml; .htm; .html; .jsp;
      .mbx; .mdx; .mht; .mmf; .msg; .nch; .ods; .oft; .php; .pl; .sht;
      .shtm; .stm; .tbb; .txt; .uin; .wab; .wsh; .xls; .xml; .dhtml


Avoid addresses:
It does not send emails to addresses containing one of the following strings:
   • @example.; 2003; 2004; 2005; 2006; @microsoft; rating@; f-secur; news;
      update; .qmail; .gif; anyone@; bugs@; contract@; feste; gold-certs@;
      help@; info@; nobody@; noone@; 0000; Mailer-Daemon@; @subscribe; kasp;
      admin; icrosoft; support; ntivi; unix; bsd; linux; listserv; certific;
      torvalds@; sopho; @foo; @iana; free-av; @messagelab; winzip; google;
      winrar; samples; spm111@; .00; abuse; panda; cafee; spam; pgp; @avp.;
      noreply; local; root@; postmaster@

 P2P In order to infect other systems in the Peer to Peer network community the following action is performed:   It searches for directories that contain one of the following substrings:
   • bear
   • donkey
   • download
   • ftp
   • htdocs
   • http
   • icq
   • kazaa
   • lime
   • morpheus
   • mule
   • shar
   • source
   • upload
   • pub

   If successful, the following files are created:
   • 1001 Sex and more.rtf; 3D Studio Max 6 3dsmax; ACDSee 10 full; Adobe
      Photoshop 10 full; Adobe Premiere 10; Ahead Nero 8; Altkins Diet.doc;
      American Idol.doc; Arnold Schwarzenegger.jpg; Best Matrix Screensaver
      new; Britney sex xxx.jpg; Britney Spears and Eminem porn.jpg; Britney
      Spears blowjob.jpg; Britney Spears cumshot.jpg; Britney Spears
      fuck.jpg; Britney Spears full album.mp3; Britney Spears porn.jpg;
      Britney Spears Sexy archive.doc; Britney Spears Song text archive.doc;
      Britney Spears.jpg; Britney Spears.mp3; Clone DVD 6; Cloning.doc;
      Cracks & Warez Archiv; Dark Angels new; Dictionary English 2004 -
      France.doc; DivX 8.0 final; Doom 3 release 2; E-Book Archive2.rtf;
      Eminem blowjob.jpg; Eminem full album.mp3; Eminem Poster.jpg; Eminem
      sex xxx.jpg; Eminem Sexy archive.doc; Eminem Spears porn.jpg;
      Eminem.mp3; Full album all.mp3; Gimp 1.8 Full with Key; Harry Potter
      1-6 book.txt; Harry Potter 5.mpg; Harry Potter all e.book.doc; Harry
      Potter e book.doc; Harry Potter game; Harry Potter.doc; Harry Potter
      and the Sorcerer's Stone game; How to hack new.doc; Internet Explorer
      9 setup; Kazaa Lite 4.0 new; Kazaa new; Keygen 4 all new; Learn
      Programming 2004.doc; Lightwave 9 Update; Magix Video Deluxe 5 beta;
      Matrix 3 .mpg; Microsoft Office 2003 Crack best; Microsoft WinXP Crack
      full; MS Service Pack 6; source code; Norton Antivirus 2005 beta;
      Opera 11 free; Partitionsmagic 10 beta; Porno Screensaver britney; RFC
      compilation.doc; Ringtones.doc; Nostradamus.doc; World Trade Center
      last video.mpeg; anthrax.doc; Osama Bin Laden.jpg; Taliban; Osama bin
      Laden.mpg; Yellow Pages; Ringtones.mp3; Saddam Hussein.jpg;
      Screensaver2; Serials edition.txt; Smashing the stack full.rtf; Star
      Office 9; Teen Porn 15.jpg; The Sims 4 beta; Ulead Keygen 2004; Visual
      Studio Net Crack all; Vista review.doc; WinAmp 13 full with sources;
      Windows Vista Sourcecode.doc; Windows 2003 crack; Windows XP crack;
      WinXP eBook newest.doc; XXX hardcore
      pics.jpg

•.exe
•.pif
•.scr

   These files are copies of the malware itself.

 Backdoor Contact server:
All of the following:
   • http://85.249.23.35/hh/ms/**********
   • http://207.46.250.119/g/**********
   • http://84.22.161.192/s/**********

As a result it may send information and remote control could be provided. This is done via the HTTP GET and POST method using a PHP script.

 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Description inserted by Andrei Gherman on Friday, May 19, 2006
Description updated by Andrei Gherman on Friday, May 19, 2006

Back . . . .