Sophos

W32/Erkez-G

Aliases
  • Email-Worm.Win32.Zafi.g
  • W32.Erkez.G@mm
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email attachments
  • Peer-to-peer
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 10 October 2005 12:59:41 (GMT)
Last updated 11 May 2006 07:29:08 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

Windows NT/2000/XP/2003

In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Zi5
<System>\AntiVirus Update.exe

and delete it if it exists.

Close the registry editor.

More Information

W32/Erkez-G is an email and peer-to-peer worm for the Windows platform.

W32/Erkez-G sends emails in the following format, where the subject and message are chosen depending upon the email address the worm is being sent to:

Subject:

msn photo ecard,commercial ecard :))
broma :)),humor :))
rolig reklam :)),haha - rolig :))
witzig reklame :)),witzig bild :D
grappig beeld :)),een grappig reclame :D
blague :)),humour - reclame :))
cherzo :)),comico quadro :))

Message:

ImageFormat: <Size>
ImageSize: <Size Kb>
Message: you need to see this :))
From: <Name>
Date: <Date sent>
AV-Control: <Filename>

Cuadro/Format: <Size>
Cuadro/Medida: <Size Kb>
Mensaje: Sexo y humor para pasar un buen rato! :))
Expedidor: <Name>
Data: <Date sent>
Control: <Filename>

Bildform: <Size>
Bild/Omfattning: <Size Kb>
Meddelande: rolig reklam!! :))
Post: <Name>
Datum: <Date sent>
Control: <Filename>

BildFormat: <Size>
Bildabmessung: <Size Kb>
Botschaft: eine witzig reklame foto :))
Absender: <Name>
Datum: <Date sent>
Kontrolle: <Filename>

Beeldformaat: <Size>
Beeldmaat: <Size Kb>
Boodschap: een ontroerend of grappig reclame :))
Afzender: <Name>
Datum: <Date sent>
Controle: <Filename>

Image/Mode: <Size>
Image/Taille: <Size Kb>
Message: le sexe d'une femme apres l'amour (humour, reclame) :))
Expediteur: <Name>
Date: <Date sent>
Verification: <Filename>

Quadro/Forma: <Size>
Quadro/Proporzioni: <Size Kb>
Messaggio: comico reclame!! :))
Mittente: <Name>
Data: <Date sent>
Controllare: <Filename>

Attachment:

The attachment name will be created using the following words, with a .zip file extension:

msn
messenger
commercial
reclame
reklame
reklam
humor
megasztar
humor
photo
pict
imag
dscn W32/Erkez-G is an email and peer-to-peer worm for the Windows platform.

When first run W32/Erkez-G copies itself to any folders it finds containg the words "musi", "shar", or "uploa" with a name of either "Adobe Acrobat 8.0 Pro.exe" or "Windows Update Crack.exe", as well as to the following locations:

<System>\AntiVirus Update.exe
<System>\antivirus_update.exe
<System>\foto5.jpz

The following registry entry is created to run "AntiVirus Update.exe" on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Zi5
<System>\AntiVirus Update.exe

The worm also creates several files in the Windows system folder with names of the format <8 random letters>.dll. Most of these are clean data files, and contain logged email details. Some may be copies of the worm.

The worm searches for email addresses in files with the following file extenstions:

dbx
asp
txt
htm
mbx
wab
php
sht
adb
tbb
inb
pmr
fpt
eml

W32/Erkez-G sends emails in the following format, where the subject and message are chosen depending upon the email address the worm is being sent to:

Subject:

msn photo ecard,commercial ecard :))
broma :)),humor :))
rolig reklam :)),haha - rolig :))
witzig reklame :)),witzig bild :D
grappig beeld :)),een grappig reclame :D
blague :)),humour - reclame :))
cherzo :)),comico quadro :))

Message:

ImageFormat: <Size>
ImageSize: <Size Kb>
Message: you need to see this :))
From: <Name>
Date: <Date sent>
AV-Control: <Filename>

Cuadro/Format: <Size>
Cuadro/Medida: <Size Kb>
Mensaje: Sexo y humor para pasar un buen rato! :))
Expedidor: <Name>
Data: <Date sent>
Control: <Filename>

Bildform: <Size>
Bild/Omfattning: <Size Kb>
Meddelande: rolig reklam!! :))
Post: <Name>
Datum: <Date sent>
Control: <Filename>

BildFormat: <Size>
Bildabmessung: <Size Kb>
Botschaft: eine witzig reklame foto :))
Absender: <Name>
Datum: <Date sent>
Kontrolle: <Filename>

Beeldformaat: <Size>
Beeldmaat: <Size Kb>
Boodschap: een ontroerend of grappig reclame :))
Afzender: <Name>
Datum: <Date sent>
Controle: <Filename>

Image/Mode: <Size>
Image/Taille: <Size Kb>
Message: le sexe d'une femme apres l'amour (humour, reclame) :))
Expediteur: <Name>
Date: <Date sent>
Verification: <Filename>

Quadro/Forma: <Size>
Quadro/Proporzioni: <Size Kb>
Messaggio: comico reclame!! :))
Mittente: <Name>
Data: <Date sent>
Controllare: <Filename>

Attachment:

The attachment name will be created using the following words, with a .zip file extension:

msn
messenger
commercial
reclame
reklame
reklam
humor
megasztar
humor
photo
pict
imag
dscn

Registry entries are created under the following branch:

HKLM\SOFTWARE\Microsoft\Zi5

The entries under this branch will locate the data and worm files with the .dll extension.

The following files are also created:

<System>\a.wsf
C:\z.m
C:\m

These are clean data files, and may safely be deleted.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer