Email-Worm.Win32.Naver

Jest to robak internetowy rozprzestrzeniaj膮cy si臋 przy u偶yciu programu MS Outlook. Szkodnik ma posta膰 uruchamialnego pliku o rozmiarze oko艂o 50 kB napisanego w j臋zyku programowania Visual Basic.

Po uruchomieniu wirus wy艣wietla okno:

naver1.gif

Gdy u偶ytkownik wci艣nie przycisk "OK" szkodnik wy艣wietla informacj臋 naver2.gif

Nast臋pnie podobnie jak po wci艣ni臋ciu przycisku "Cancel" robak instaluje si臋 w systemie. Kopiuje si臋 do katalogu Windows z nazw膮 WINSYS.EXE oraz do katalogu systemowego Windows z nazw膮 WINSYS.EXE. Drugi plik jest umieszczany w sekcji auto-run rejestru systemowego:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindows
CurrentVersionRun WLWin = %windir%WINSYS.EXE

Ponadto robak tworzy dodatkowy klucz s艂u偶膮cy do oznaczania zainfekowanych komputer贸w:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindows
CurrentVersion WLKey = 1

W katalogu systemowym Windows wirus tworzy r贸wnie偶 plik NAVER.TXT i zapisuje do niego tekst wykorzystywany w tre艣ci zainfekowanych wiadomo艣ci (patrz poni偶ej).

Nast臋pnie robak 艂膮czy si臋 z ksi膮偶k膮 adresow膮 programu MS Outlook i wysy艂a zainfekowane wiadomo艣ci do u偶ytkownik贸w w niej zapisanych. Wiadomo艣ci wygl膮daj膮 nast臋puj膮co:

Temat:

Re: Windows Upgrade
Tre艣膰:
Use this patch!!, goodbye 

From: "Micosoft upgrades" 
To: "Windows users" 
Subject: Upgrade
Date: Mon, 11 Jun 2001 11:02:34 +0200 

Microsoft programs bugs that are costantly found, are immediately often solved 
by little patches, that are regulary pubblished on the official site, but despite this only few
users use this patches. Because of this a lot of users consider Microsoft systems
unsecure, you can solve all the problems at base, upgrading costantly the system,
because of this Microsoft沤 decided to exploit FAQ mail to reach the majority of users.
By FAQ mail you have recived it, that contain the first upgrade, naver.exe file
(Upgrade 11 Jun 2001), an upgrade that is used for increase security of Windows 
system protocol TCP/IP problems and for SSL (Secure Sockets Layer) secure system exploration.
For a correct operation copy naver.exe in c: and run it

Forward this mail at your friends with the relative attachment or if 
you don't want to receive any other upgrades send an empty mail to 
deletelist@microsoft.com with subject "Delete from database". 

We thank in advance all the users that will agree the project.

Answerable Microsoft沤 Upgrades John Milton
http://www.microsoft.com/security/

Nazwa za艂膮czonego pliku: NAVER.EXE

W pewnych przypadkach (najprawdopodobniej w zale偶no艣ci od daty systemowej) robak usuwa swoje klucze rejestru oraz pliki i wy艣wietla wiadomo艣膰:

VIRUS !!!!!!!!!!!
Virus Eclisse has infected
Don't try to close the counter before zero otherwise it will be restarted,
the system will be released only when the countdown counts zero.

Now you are able to use your computer, this Virus automatically delete
itself, byez. ( Translation by M_O_R_B_O )