Email-Worm.Win32.Naver
Po uruchomieniu wirus wy艣wietla okno:
Gdy u偶ytkownik wci艣nie przycisk "OK" szkodnik wy艣wietla
informacj臋
Nast臋pnie podobnie jak po wci艣ni臋ciu przycisku "Cancel" robak instaluje si臋 w systemie. Kopiuje si臋 do katalogu Windows z nazw膮 WINSYS.EXE oraz do katalogu systemowego Windows z nazw膮 WINSYS.EXE. Drugi plik jest umieszczany w sekcji auto-run rejestru systemowego:
CurrentVersionRun WLWin = %windir%WINSYS.EXE
Ponadto robak tworzy dodatkowy klucz s艂u偶膮cy do oznaczania zainfekowanych komputer贸w:
CurrentVersion WLKey = 1
W katalogu systemowym Windows wirus tworzy r贸wnie偶 plik NAVER.TXT i zapisuje do niego tekst wykorzystywany w tre艣ci zainfekowanych wiadomo艣ci (patrz poni偶ej).
Nast臋pnie robak 艂膮czy si臋 z ksi膮偶k膮 adresow膮 programu MS Outlook i wysy艂a zainfekowane wiadomo艣ci do u偶ytkownik贸w w niej zapisanych. Wiadomo艣ci wygl膮daj膮 nast臋puj膮co:
Temat:
Re: Windows UpgradeTre艣膰:
Use this patch!!, goodbye From: "Micosoft upgrades" To: "Windows users" Subject: Upgrade Date: Mon, 11 Jun 2001 11:02:34 +0200 Microsoft programs bugs that are costantly found, are immediately often solved by little patches, that are regulary pubblished on the official site, but despite this only few users use this patches. Because of this a lot of users consider Microsoft systems unsecure, you can solve all the problems at base, upgrading costantly the system, because of this Microsoft沤 decided to exploit FAQ mail to reach the majority of users. By FAQ mail you have recived it, that contain the first upgrade, naver.exe file (Upgrade 11 Jun 2001), an upgrade that is used for increase security of Windows system protocol TCP/IP problems and for SSL (Secure Sockets Layer) secure system exploration. For a correct operation copy naver.exe in c: and run it Forward this mail at your friends with the relative attachment or if you don't want to receive any other upgrades send an empty mail to deletelist@microsoft.com with subject "Delete from database". We thank in advance all the users that will agree the project. Answerable Microsoft沤 Upgrades John Milton http://www.microsoft.com/security/
Nazwa za艂膮czonego pliku: NAVER.EXE
W pewnych przypadkach (najprawdopodobniej w zale偶no艣ci od daty systemowej) robak usuwa swoje klucze rejestru oraz pliki i wy艣wietla wiadomo艣膰:
VIRUS !!!!!!!!!!! Virus Eclisse has infected Don't try to close the counter before zero otherwise it will be restarted, the system will be released only when the countdown counts zero. Now you are able to use your computer, this Virus automatically delete itself, byez. ( Translation by M_O_R_B_O )