Virus: Worm/Tearec.A Date discovered: 12/10/2006 Type: Worm In the wild: Yes Reported Infections: Low Distribution Potential: Medium to high Damage Potential: Medium Static file: Yes File size: 94.154 Bytes MD5 checksum: 1c237c5af9c4c344eaac451b2ef5459c VDF version: 6.36.00.97 IVDF version: 6.36.00.113 - Monday, October 16, 2006
General Methods of propagation: • Email • Local network Aliases: • Kaspersky: Email-Worm.Win32.Nyxem.e • TrendMicro: WORM_NYXEM.AA • F-Secure: Email-Worm.Win32.Nyxem.e • Sophos: W32/Nyxem-H • Panda: W32/Tearec.B.worm • Eset: Win32/Nyxem.NAA worm • Bitdefender: Win32.Nyxem.H@mm Platforms / OS: • Windows 95 • Windows 98 • Windows 98 SE • Windows NT • Windows ME • Windows 2000 • Windows XP • Windows 2003 Side effects: • Disable security applications • Uses its own Email engine • Lowers security settings • Registry modification Right after execution the following information is displayed: Files It copies itself to the following locations: • %WINDIR% \Rundll16.exe • %SYSDIR% \scanregw.exe • C:\WINZIP_TMP.exe • %SYSDIR% \Update.exe • %SYSDIR% \Winzip.exe • %ALLUSERSPROFILE%\Start Menu\Programs\Startup\WinZip Quick Pick.exe It overwrites the following files. The build-in time synchronisation will trigger on the following point of time: If day equals the following value: 3 – %all directories% File extensions: • .HTM • .DBX • .EML • .MSG • .OFT • .NWS • .VCF • .MBX With the following contents: • DATA Error [47 0F 94 93 F4 K5] It deletes the following files: • %PROGRAM FILES% \DAP\*.dll • %PROGRAM FILES% \BearShare\*.dll • %PROGRAM FILES% \Symantec\LiveUpdate\*.* • %PROGRAM FILES% \Trend Micro\PC-cillin 2003\*.exe • %PROGRAM FILES% \Symantec\Common Files\Symantec Shared\*.* • %PROGRAM FILES% \Norton AntiVirus\*.exe • %PROGRAM FILES% \Alwil Software\Avast4\*.exe • %PROGRAM FILES% \McAfee.com\VSO\*.exe • %PROGRAM FILES% \McAfee.com\Agent\*.* • %PROGRAM FILES% \McAfee.com\shared\*.* • %PROGRAM FILES% \Trend Micro\PC-cillin 2002\*.exe • %PROGRAM FILES% \Trend Micro\Internet Security\*.exe • %PROGRAM FILES% \NavNT\*.exe • %PROGRAM FILES% \Kaspersky Lab\Kaspersky Anti-Virus Personal\*.ppl • %PROGRAM FILES% \Kaspersky Lab\Kaspersky Anti-Virus Personal\*.exe • %PROGRAM FILES% \Grisoft\AVG7\*.dll • %PROGRAM FILES% \TREND MICRO\OfficeScan\*.dll • %PROGRAM FILES% \Trend Micro\OfficeScan Client\*.exe • %PROGRAM FILES% \LimeWire\LimeWire 4.2.6\LimeWire.jar • %PROGRAM FILES% \Morpheus\*.dll • %PROGRAM FILES% \CA\eTrust EZ Armor\eTrust EZ Antivirus\*.* • %PROGRAM FILES% \Common Files\symantec shared\*.* • %PROGRAM FILES% \Kaspersky Lab\Kaspersky Anti-Virus Personal\*.* • %PROGRAM FILES% \Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\*.* • %PROGRAM FILES% \McAfee.com\Agent\*.* • %PROGRAM FILES% \McAfee.com\shared\*.* • %PROGRAM FILES% \McAfee.com\VSO\*.* • %PROGRAM FILES% \NavNT\*.* • %PROGRAM FILES% \Norton AntiVirus\*.* • %PROGRAM FILES% \Panda Software\Panda Antivirus 6.0\*.* • %PROGRAM FILES% \Panda Software\Panda Antivirus Platinum\*.* • %PROGRAM FILES% \Symantec\LiveUpdate\*.* • %PROGRAM FILES% \Trend Micro\Internet Security\*.* • %PROGRAM FILES% \Trend Micro\PC-cillin 2002\*.* • %PROGRAM FILES% \Trend Micro\PC-cillin 2003 \*.* Registry The following registry key is added in order to run the process after reboot: – HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run • ScanRegistry = "scanregw.exe /scan" The values of the following registry keys are removed: – HKLM\Software\Microsoft\Windows\CurrentVersion\Run • CleanUp • SECUR • NPROTECT • ccApp • ScriptBlocking • MCUpdateExe • VirusScan Online • MCAgentExe • VSOCheckTask • McRegWiz • MPFExe • MSKAGENTEXE • MSKDetectorExe • McVsRte • PCClient.exe • PCCIOMON.exe • pccguide.exe • Pop3trap.exe • PccPfw • tmproxy • McAfeeVirusScanService • NAV Agent • PCCClient.exe • SSDPSRV • rtvscn95 • defwatch • vptray • ScanInicio • APVXDWIN • KAVPersonal50 • kaspersky • TM Outbreak Agent • AVG7_Run • AVG_CC • Avgserv9.exe • AVGW • AVG7_CC • AVG7_EMC • Vet Alert • VetTray • OfficeScanNT Monitor • avast! • PANDA • DownloadAccelerator • BearShare – HKCU\Software\Microsoft\Windows\CurrentVersion\Run • CleanUp • SECUR • NPROTECT • ccApp • ScriptBlocking • MCUpdateExe • VirusScan Online • MCAgentExe • VSOCheckTask • McRegWiz • MPFExe • MSKAGENTEXE • MSKDetectorExe • McVsRte • PCClient.exe • PCCIOMON.exe • pccguide.exe • Pop3trap.exe • PccPfw • tmproxy • McAfeeVirusScanService • NAV Agent • PCCClient.exe • SSDPSRV • rtvscn95 • defwatch • vptray • ScanInicio • APVXDWIN • KAVPersonal50 • kaspersky • TM Outbreak Agent • AVG7_Run • AVG_CC • Avgserv9.exe • AVGW • AVG7_CC • AVG7_EMC • Vet Alert • VetTray • OfficeScanNT Monitor • avast! • PANDA • DownloadAccelerator • BearShare The following registry keys including all values and subkeys are removed: • Software\INTEL\LANDesk\VirusProtect6\CurrentVersion • SOFTWARE\Symantec\InstalledApps • SOFTWARE\KasperskyLab\InstalledProducts\Kaspersky Anti-Virus Personal • SOFTWARE\KasperskyLab\Components\101 • SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Iface.exe • SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Panda Antivirus 6.0 Platinum The following registry keys are changed: Various Explorer settings: – HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced New value: • "WebView"=dword:00000000 • "ShowSuperHidden"=dword:00000000 Various Explorer settings: – [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ CabinetState] New value: • "FullPath" = dword:00000001 Email It contains an integrated SMTP engine in order to send emails. A direct connection with the destination server will be established. The characteristics are described in the following: To: – Email addresses found in specific files on the system. – Email addresses gathered from WAB (Windows Address Book) –Email addresses gathered from Yahoo! Messenger –Email addresses gathered from MSN Messenger Subject: One of the following: • Word file; eBook.pdf; the file; Part 1 of 6 Video clipe; You Must View This Videoclip!; Miss Lebanon 2006; Re: Sex Video; My photos; The Best Videoclip Ever; School girl fantasies gone bad; A Great Video; Fuckin Kama Sutra pics; Arab sex DSC-00465.jpg; give me a kiss; *Hot Movie*; Fw: Funny :); Fwd: Photo; Fwd: image.jpg; Fw: Sexy; Re:; Fw:; Fw: Picturs; Fw: DSC-00465.jpg In some cases the subject might also be empty. Body: The body of the email is one of the lines: • ----- forwarded message ----- • ???????????????????????????? ????????????? ?????? ??????????? • >> forwarded message • DSC-00465.jpg DSC-00466.jpg DSC-00467.jpg • forwarded message attached. • Fuckin Kama Sutra pics • hello, i send the file. bye • hi i send the details bye • Hot XXX Yahoo Groups • how are you? i send the details. OK ? • i attached the details. Thank you • i just any one see my photos. It's Free :) • Note: forwarded message attached. • photo photo2 photo3 • Please see the file. • ready to be FUCKED :) • VIDEOS! FREE! (US$ 0,00) • What? Attachment: The filename of the attachment is one of the following: • 007.pif; 04.pif; 392315089702606E-02,.scR; 677.pif; Adults_9,zip.sCR; Arab sex DSC-00465.jpg; ATT01.zip.sCR; Attachments[001],B64.sCr; Clipe,zip.sCr; document.pif; DSC-00465.Pif; DSC-00465.pIf; DSC-00465.Pif; DSC-00465.pIf; eBook.pdf; eBook.PIF; image04.pif; image04.pif; New Video,zip; New_Document_file.pif; photo.pif; Photos,zip.sCR; School.pif; SeX,zip.scR; Sex.mim; Video_part.mim; WinZip,zip.scR; WinZip.BHX; WinZip.zip.sCR; Word XP.zip.sCR; Word.zip.sCR The attachment is a copy of the malware itself. Mailing Search addresses: It searches the following files for email addresses: • *.doc; *.xls; *.mdb; *.mde; *.ppt; *.pps; *.zip; *.rar; *.pdf; *.psd; *.dmp Avoid addresses: It does not send emails to addresses containing one of the following strings: • SYMANTEC; KASPERSKY; VIRUS; MCAFEE; TREND MICRO; PANDA; NORTON; FIX; HOTMAIL.COM; HELO; SECUR; SCRIBE; SPAM; ANTI; CILLIN; CA.COM; KASPER; TRUST; AVG; GROUPS.MSN; NOMAIL.YAHOO.COM; EEYE; MICROSOFT; @HOTMAIL; gmail.com; myway.com; @HOTPOP; @YAHOOGROUPS; @yahoo.com Resolving server names: It has the ability to contact the DNS server: • ns1.%receiver's domain name from email address% Network Infection In order to ensure its propagation the malware attemps to connect to other machines as described below. It drops copies of itself to the following network shares: • ADMIN$ • C$ It uses the following login information in order to gain access to the remote machine: – The following username: • administrator Remote execution: –It attempts to schedule a remote execution of the malware, on the newly infected machine. Therefore it uses the NetScheduleJobAdd function. Process termination Processes containing one of the following window titles are terminated: • SYMANTEC • SCAN • KASPERSKY • VIRUS • MCAFEE • TREND MICRO • NORTON • REMOVAL • FIX Backdoor Contact server: The following: • http://webstats.web.rcn.net/**********?df=778247 As a result it may send some information. This is done via the HTTP POST method using a CGI script. Sends information about: • Current malware status File details Programming language: The malware program was written in Visual Basic. Runtime packer: In order to aggravate detection and reduce size of the file it is packed with the following runtime packer: • UPX
Description inserted by Alexandru Dinu on Wednesday, November 14, 2007 Description updated by Alexandru Dinu on Friday, November 16, 2007
Back
.
.
.
.