Main Menu
Home
Bookmark
Contact Us



 
I-Worm.Pepex. Viruses Information

Name: I-Worm.Pepex.
Category: Viruses
Description: Details
I-Worm.Pepex.a
"Pepex" is a worm virus spreading via the Internet as an attachment to infected emails and also through the Kazaa network and IRC channels.
The worm itself is a Windows PE EXE file about 32KB in length (when compressed by UPX, the decompressed size is about 80KB). "Pepex" is written in Microsoft Visual C++.
Infected messages have the following message field attributes:
From: "Microsoft" < information@microsoft.com >
Reply-To: "Microsoft" < microsoft@microsoft.com >
Subject: Internet Explorer vulnerability patch
Body: You will find all you need in the attachment.
Attach: setup.exe

The worm activates from infected emails only when a user clicks on the attached file. 'Pepex' then installs itself to the system and runs its spreading routines.
Installing
While installing, the worm copies itself to the Windows system directory with the winsys???.exe name (where '???' is a random three-digit number) and registers this file in the system registry auto-run key:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun
Windows task32 sys = %SystemDir%winsys???.exe

Above, %SystemDir% represents the Windows System directory path.
The worm then creates a ZIP archive with its "winsys???.exe" copy inside. The archive is created with the help of the WinZip32 utility (if it is installed). The archive name is "win32sys???.zip" (where '???' is the same random number). This archive is used later to spread through IRC channels.
The worm also creates a system registry key to mark already infected systems:
HKEY_LOCAL_MACHINESoftwareRedCell
infected = yes
The worm also looks for active processes that have "AV" or "av" letters in their names (anti-virus programs) and tries to terminate them.
Spreading: EMail

To send infected messages the worm uses a direct connection to an SMTP server (if it is registered), or to the "smtp.barrysworld.com" server. To get victim emails the worm scans files with the ".htm" extension in the "Temporary Internet Files" directory. While spreading the worm also creates a file named C:Msbootlog.sys to where its MIME encoded copy is written.
Spreading: IRC

The worm creates the SCRIPT.INI file in mIRC directory and writes a command to it. This command sends infected "win32sys???.zip" file (see above) to IRC users that join infected channel.
Spreading: Kazaa

The worm copies itself to Kazaa directory with a randomly selected name:
icq2002.exe
wincrack.exe mirc6.exe

Other
After installation the worm displays a fake error message:



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Pantera.40
Metallica.50
DirII.TheHndv.
Terronia Famil
Lobotomy Famil
I-Worm.GOPWor
I-Worm.Badtrans.
WWPE.Rsa.456
Worm.Info Famil
Fantom.95


 


© 2006-2008 spyware32.com - Privacy Policy