Sophos

W32/Alasrou-A

Aliases
  • Net-Worm.Win32.Small.d
  • W32/Alasrou
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 2 September 2005 13:10:56 (GMT)
Last updated 11 October 2005 19:50:10 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

You should also check your Internet Explorer settings using Tools|Internet options|General for any modifications made by the worm.

Windows NT/2000/XP/2003

In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Instance 001
<pathname of the worm executable>

and delete it if it exists.

Close the registry editor.

More Information

W32/Alasrou-A is an email address harvesting worm for the Windows platform.

W32/Alasrou-A spreads to other network computers by exploiting common buffer
overflow vulnerabilites, including LSASS (MS04-011).

W32/Alasrou-A includes functionality to download, install and run new software. W32/Alasrou-A is an email address harvesting worm for the Windows platform.

W32/Alasrou-A spreads to other network computers by exploiting common buffer
overflow vulnerabilites, including LSASS (MS04-011).

W32/Alasrou-A includes functionality to download, install and run new software.

When W32/Alasrou-A is installed the following files are created:

<Temp>\file1.exe
<System>\searchpage.htm

File1.exe is downloaded from a remote server, and searchpage.htm is set as the
default search page for Internet Explorer.

W32/Alasrou-A also searches for the file thebat.abd, and files with the following extensions, harvesting email addresses:

.tbb
.dbx
.nk2
.wab

The collected emails are then uploaded to a remote FTP server.

The following registry entry is created to run W32/Alasrou-A on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Instance 001
<pathname of the worm executable>

W32/Alasrou-A changes settings for Microsoft Internet Explorer, including the Start Page and Search Page, by modifying values under:

HKCU\Software\Microsoft\Internet Explorer\Security\
HKCU\Software\Microsoft\Internet Explorer\Main\Search Page
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer