Chinese Internet Security Response Team (GMT +0800)

Chirstmas-2007.zip Spreads via MSN

[Post on : December 25, 2007 17:53 | Category : Worm | by : smallmo] Reship : Original

We received some reports that a .zip file "chirstmas-2007.zip" was spreading via MSN Messenger. This worm also sends out the following message:
Christmas photo! :D
vengo de fi este foto
lbum
Hey i que hace el
lbum de foto! Si vea el loL del em
xmas photo!: D
haha :D
lol, christmas pictures off me
hola, My Christmas picture for you :)


In the .zip file, it contains a double extension file "img2007-12.JPEG.scr". The size is 56,065 bytes, MD5 hash is 0c222d6191212a52ae70a8283eb7c316. Kaspersky detects it as IM-Worm.Win32.Agent.av.

Upon execution, it drops the following files:
%Windows%\chirstmas-2007.zip
%Windows%\servidevice.exe


It creats the following registry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"ryan1918" = "servidevice.exe"


Update 12:10 p.m. Dec.26,2007:

Mcafee detects this worm as W32/Checkout!0e4a3c52




Last modified by smallmo onDecember 26, 2007 12:10

smallmo Says : Email Homepage
December 26, 2007 11:20
Hello, caii. All the copyright information can be seen here.
caii Says : Email Homepage
December 26, 2007 09:08
Thank you very much.

Btw, you should not remove the copyright information of Bo-Blog.
Pages: 1/1 First page 1 Final page