Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 2nd, 2002, 02:30 PM
FanJ
 
Posts: n/a
Default W32/Zoek-D

Name: W32/Zoek-D
Aliases: I-Worm.Zoek.d, W32/Tcasut
Type: Win32 worm
Date: 2 July 2002



Sophos has received several reports of this worm from the wild.

Note: This IDE file also includes updated detection for
Troj/BO-2000.

More information about W32/Zoek-D can be found at
http://www.sophos.com/virusinfo/analyses/w32zoekd.html

  #2  
Old July 2nd, 2002, 02:33 PM
FanJ
 
Posts: n/a
Default Re:W32/Zoek-D

W32/Zoek-D is an email worm. When the worm is run it will send a copy of itself to one entry from the Microsoft Outlook address book. The worm will black out the screen and display 'One moment please' in large yellow letters across the top. After a few seconds a large button will appear with the text 'Windows Restart?'. Clicking on this button will cause Windows to shutdown and restart.

The worm arrives in an email with the following charactistics:

Subject line: Maxima Screensaver!
Attached file: screenmaxima.scr

The body of the email will be blank.

The worm will copy itself to C:\Windows\Tcasuta.exe, drop another executable in C:\Windows\System\Tcasutb.exe and add the following registry entry so that tcasutb.exe is run each time Windows is started:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\tcasutb.exe

Tcasutb.exe is a variant of Troj/BO-2000.

The worm will generate several files in C:\Windows containing configuration
information about the host computer and encoded copies of the worm. The following files are created:

accountboy.ini
attachready.ini
hoen.txt
ipinfo.txt
mailboy.ini
mailready.ini
passboy.ini
ratmailready.ini
secretsmailready.ini
tcasuta.txt

Some of these files may have the Hidden attribute set.

The worm will email some of this information (such as the IP address) to a remote email address.
  #3  
Old July 2nd, 2002, 02:47 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:W32/Zoek-D

mmm..coded with the Dutch audience in mind for sure - coded by a Dutchie without any doubt

regards,

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #4  
Old July 2nd, 2002, 02:53 PM
FanJ
 
Posts: n/a
Default Re:W32/Zoek-D

Yep

For the non-Dutchies:
Quote:
Subject line: Maxima Screensaver!

Maxima is the wife of the Dutch crown-prince.
  #5  
Old July 2nd, 2002, 02:56 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:W32/Zoek-D

Quote:
Maxima is the wife of the Dutch crown-prince.

Did they marry in the meanwhile? No longer living in sin?

regards,

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #6  
Old July 2nd, 2002, 03:33 PM
FanJ
 
Posts: n/a
Default Re:W32/Zoek-D

Quote:
quoting: Forum Admin link=board=31;threadid=2133;start=0#15285 date=1025636200]
Did they marry in the meanwhile? No longer living in sin?

see http://www.koninklijkhuis.nl/nl/huwelijk/
  #7  
Old July 2nd, 2002, 03:39 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,461
Default Re:W32/Zoek-D

ahh..thanks Jan!

Guess the monarchy has been saved!

regards,

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 01:36 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums