Alerts
Posted: Mon Aug 09, 2004 7:28 am
W32.Amus.A@mm
Discovered on: August 06, 2004
Last Updated on: August 07, 2004 12:44:25 PM
W32.Amus.A@mm is a mass-mailing worm that sends email with the subject "Listen and Smile" and the attachment "Masum.exe."
Also Known As: WORM_AMUS.A (Trend), Amus.A (Panda), Amus.A (F-Secure)
Type: Worm
Infection Length: 51,782 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows CE
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Yes
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: Listen and Smile
Name of attachment: Masum.exe
Size of attachment: 51,782 bytes
Time stamp of attachment: varies
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Amus.A@mm runs, it does the following:
Adds the value:
"Microzoft_Ofiz"="%Windir%\KdzEregli.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Adds the value:
"Who"="OnEmLi_DeGiL"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Masum
Copies itself to the %Windir% folder as:
Pire.exe
Pide.exe
My_Pictures.exe
Meydanbasi.exe
Messenger.exe
KdzEregli.exe
Cekirge.exe
Anti_Virus.exe
Ankara.exe
Adapazari.exe
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Copies itself as C:\Masum.exe.
Uses Microsoft Outlook to send itself to all the contacts in the Microsoft Outlook Address Book.
The email has the following characteristics:
Subject: Listen and Smile
Message Body: Hey. I beg your pardon. You must listen.
Attachment: Masum.exe
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Amus.A@mm.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Microzoft_Ofiz"="%Windir%\KdzEregli.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
In the right pane, delete the subkey:
Masum
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.amus.a@mm.html\"]Symantec Source[/url]
Discovered on: August 06, 2004
Last Updated on: August 07, 2004 12:44:25 PM
W32.Amus.A@mm is a mass-mailing worm that sends email with the subject "Listen and Smile" and the attachment "Masum.exe."
Also Known As: WORM_AMUS.A (Trend), Amus.A (Panda), Amus.A (F-Secure)
Type: Worm
Infection Length: 51,782 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, EPOC, Linux, Macintosh, Macintosh OS X, Novell Netware, OS/2, UNIX, Windows 3.x, Windows 64-bit (AMD64), Windows 64-bit (IA64), Windows CE
Damage
Payload Trigger: n/a
Payload: n/a
Large scale e-mailing: Yes
Deletes files: n/a
Modifies files: n/a
Degrades performance: n/a
Causes system instability: n/a
Releases confidential info: n/a
Compromises security settings: n/a
Distribution
Subject of email: Listen and Smile
Name of attachment: Masum.exe
Size of attachment: 51,782 bytes
Time stamp of attachment: varies
Ports: n/a
Shared drives: n/a
Target of infection: n/a
When W32.Amus.A@mm runs, it does the following:
Adds the value:
"Microzoft_Ofiz"="%Windir%\KdzEregli.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
Adds the value:
"Who"="OnEmLi_DeGiL"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Masum
Copies itself to the %Windir% folder as:
Pire.exe
Pide.exe
My_Pictures.exe
Meydanbasi.exe
Messenger.exe
KdzEregli.exe
Cekirge.exe
Anti_Virus.exe
Ankara.exe
Adapazari.exe
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Copies itself as C:\Masum.exe.
Uses Microsoft Outlook to send itself to all the contacts in the Microsoft Outlook Address Book.
The email has the following characteristics:
Subject: Listen and Smile
Message Body: Hey. I beg your pardon. You must listen.
Attachment: Masum.exe
Removal Instructions:
Disable System Restore (Windows Me/XP).
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Amus.A@mm.
Delete the value that was added to the registry.
To delete the value from the registry
Important: Symantec strongly recommends that you back up the registry before making any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry," for instructions.
Click Start > Run.
Type regedit
Then click OK.
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
In the right pane, delete the value:
"Microzoft_Ofiz"="%Windir%\KdzEregli.exe"
Navigate to the key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\
In the right pane, delete the subkey:
Masum
Exit the Registry Editor.
[url=\"http://securityresponse.symantec.com/avcenter/venc/data/w32.amus.a@mm.html\"]Symantec Source[/url]