-
Worm 'Nyxem.e' spreading fast, raises concern
Nyxem.e' is a mass-mailing worm that carries a "nuclear option" payload that corrupts data in popular file formats, it also spreads using remote shares.
It accounts for 1 out of every 15 pieces of malicious code. It is similar to the 'Email-Worm.Win32.VB.bi' that was found a few days ago.
F-Secure disclosed that Nyxem.e worm, carries code that instructs it to replace data in files with .doc, .xls, .mdb, .mde, .ppt, .pps, .zip, .rar, .pdf, .psd, or .dmp extensions with the useless string "DATA Error [47 0F 94 93 F4 K5]" on the third of the month.
The viciousness of the worm can also be gauged by the fact that it tries delete selected security software. It also spreads through shared folders and by addresses hijacked from infected PCs.
The way the mails arrive have lead various security sites to dub it as 'kama sutra worm'. It arrives as an attachment to e-mail messages with a variety of subject headlines, many of which tout porn with phrases like "Arab sex," "give me a kiss," "Hot Movie," and "F***** Kama Sutra pics."
Details about the worm :
Nyxem.E is written in Visual Basic and is compiled as p-code. The size of the main executable is about 95 kilobytes. When executed the worm, it first copies itself to several locations.
* %Windows%\rundll16.exe
* %System%\scanregw.exe
* %System%\Update.exe
* %System%\Winzip.exe
Startup entries :
[HKLM\Software\Microsoft\Windows\CurrentVersion\Run ]"ScanRegistry" = "%System%\scanregw.exe /scan
Details about the extensions infected & mail headers :
Payload :
The worm has a dangerous payload. On every 3rd day of a month after the worm's UPDATE.EXE file is run, it destroys files with those extensions on all available drives, The file contents get replaced with a text string "DATA Error [47 0F 94 93 F4 K5]".
* *.doc
* *.xls
* *.mdb
* *.mde
* *.ppt
* *.pps
* *.zip
* *.rar
* *.pdf
* *.psd
* *.dmp
The worm collects e-mail addresses from files with following extensions :
* .HTM
* .DBX
* .EML
* .MSG
* .OFT
* .NWS
* .VCF
* .MBX
* .IMH
* .TXT
* .MSF
Mail headers :
* The Best Videoclip Ever
* School girl fan***** gone bad
* A Great VideoF****
* Kama Sutra pics
* Arab ***
* DSC-00465.jpg
* give me a ki***Hot Movie*
* Fw: Funny
* Fwd: Photo
* Fwd: image.jpg
* Fw: Sexy
* Re:
* Fw:
* Fw: Picturs
* Fw: DSC-00465.jpg
* Word file
* eBook.pdf
* the file
* Part 1 of 6 Video clipe
* You Must View This Videoclip!
* Miss Lebanon 2006
* Re: S** Video
* My photos
Infection counter :
The worm has an interesting feature. When it infects a computer it opens a web browser on a certain webpage. This increments the counter on that webpage. At the moment the counter is close to 400000.
Update :
The worm 'Nyxem.e' is scheduled to create havoc on 3rd February.
The worm was accounting for about 35 percent of virus traffic as of Monday morning. It seems, the worm is still spreading, albeit a bit more slowly.
The fact is, it is still gaining ground and with the payload it is carrying it can cause wide spread damage by overwriting your crucial microsoft and adobe documents.
"On Friday the counter was at 270,000," said Hypponen, "but early Monday, it was at 680,000. That's 400,000 PCs that have been infected in one weekend."
Also Known As :
W32.Blackmal.E@mm[Symantec], WORM_GREW.{A, B} [Trend Micro], W32/Nyxem-D [Sophos], W32/MyWife.d@MM [McAfee], Email-Worm.Win32.VB.bi, Email-Worm.Win32.Nyxem.e [F-Secure], W32/Small.KI@mm [Norman], Win32/Blackmal.F [Computer Associates], Tearec.A [Panda Software]
Systems Affected :
Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Norton has released a removal tool :
To download the removal tool click here.
__________________________
Just In :
'Nyxem.e' fools windows by spoofing digital certificates.
The security threat posed by worm 'Nyxem.e' has just gone up the roof because of a new finding made by the security company Fortinet.
It seems the worm fools windows into accepting malicious activex control's by spoofing digital certificates.
It achieves this by adding 18 entries to the Windows Registry which helps the ActiveX control slip through the operating system's defences. In another words by adding those registry entries it makes the control look like 'safe' and 'digitally signed' in eyes of the operating system.
"If a worm puts a fake certificate on an infected machine, MITM [Man-In-The-Middle] attacks become extremely easy.
dipdude's Avatar
dipdude
Die Tryin'
Join Date: May 2005
Location: India
Posts: 1,395
dipdude is highly Admirabledipdude is highly Admirabledipdude is highly Admirabledipdude is highly Admirabledipdude is highly Admirabledipdude is highly Admirabledipdude is highly Admirabledipdude is highly Admirable
References
http://secunia.com/virus_information/26334/nyxem.e/
http://www.f-secure.com/v-descs/nyxem_e.shtml
http://www.informationweek.com/story...1&cid=RSSfeed_ IWK_News
http://[email protected]
http://www.itnews.com.au/newsstory.a...ID=23728&r=rss
http://www.pcworld.com/resource/arti...RSS,RSS,00.asp
http://www.itnews.com.au/newsstory.a...ID=27889&r=rss
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
Bookmarks