|
|
I-Worm.Kelin Viruses Information
| Name: |
I-Worm.Kelin |
| Category: |
Viruses |
| Description:
|
Details
I-Worm.Kelino
This worm virus spreads via the Internet being attached to infected emails. The worm itself is a Windows PE EXE file with a length of about 12Kb, written in Assembler.
The infected messages have different data depending on the worm version:
From (two variants):
"Microsoft Support"
"Microsoft HelpBoard"
Subject: Support Message
Body (first variant):
During the last time, many bugs were found in our software. Because
of our product philosophie, we want to give our custumers as much security
as possible. So we decided to send out to all known Microsoft custumers the
NetBios patch Version 1.0 . This patch will fix all the known and possibly unknown
bugs and securityholes on port 137 and 139 .
The patch is completly free and easy to install. Our patch will install
itself after starting and run as background process. After a successfull
installation you should get an OK message box.
Thanx for using Microsoft products.
Your Microsoft Support Team
Body (second variant):
During the last time, some bugs were found in our software. Because
of our product philosophy, we want to give our customers as much security
as possible. So, we decided to send out to all known Microsoft custumers the
Security patch Version 1.0 . This patch will fix all the
bugs and securityholes on port 137 and 139 .
The patch is completly free and easy to install. Our patch will install
itself after starting and run as background process. After a successfull
installation you should get a confirmation message box.
Thank you for using Microsoft products.
Your Microsoft Support Team
Attachment:
netbiospatch10.exe
secpatch10.exe
The worm activates from infected email only if a user clicks on the attached file. The worm then installs itself to the system, runs its spreading routine and payload.
Installing
While installing the worm copies itself to the Windows directory with one of the following names (depending on worm version):
netbiospatch10.exe
secpatch10.exe
and registers its copy in the system registry auto-run key (depending on worm version):
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
netpatch = netbiospatch10.exe
secpatch = secpatch10.exe
The worm then displays a fake error message:
KERNEL32 ERROR
Couldn't execute frame buffer!
Spreading
To send infected messages the worm gets email addresses from WAB database and connects to default SMTP server.
The worm also sends notification message with empty body to its author:
From: "Kelaino"
To: kelaino@freenet.de
Subject: Slave Message |
Top Viruses Visited Pages:
Invader. - 231 visits
not-a-virus:RiskWare.Tool.RegPatch. - 69 visits
Worm.P2P.Harex. - 63 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 55 visits
Small.58. - 55 visits
Coito.64 - 53 visits
I-Worm.Mapson. - 45 visits
Win16.Klon.1177 - 41 visits
Win32.Hidra - 41 visits
Marine.500 - 34 visits
Random Viruses Pages:
Cracky.59
Peterburg.52
I-Worm.Mydoom.a
Win32.TeddyBea
Etc.70
Lct.59
TrojanSpy.Win32.Small.
Gratug.48
Win95.Murkry.39
Anarchy.66
|
|