Sophos

W32/Evaman-F

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email messages
  • Email attachments
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 30 September 2004 11:15:00 (GMT)
Last updated 12 October 2004 19:42:14 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Evaman-F is an email worm for the Windows platform.

When first run, W32/Evaman-F copies itself to the Windows system folder with the filename syshost.exe. In order to run on system start, the worm creates the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
MS Update = C:\WINDOWS\System32\syshost.exe

W32/Evaman-F harvests email addresses from files on the infected machines which have file extensions contained within any of the following strings:

txt
htmb
htmlb
shtl
phpq
emll
msgq
aspd
dbxn
tbbg
adbh
pl
wab

The worm avoids sending itself to any email addresses containing the following:

icrosof
syma
msn
hotmail
anda
opho
borlan
npris
xample
mydom
@domai
ruslis
.gov
.gov
.mil
@foo
berkeley
unix
math
bsd
mit.e
gnu
fsf.
ibm
oogle
kernel
linux
fido
senet
@iana
ripe
isi.e
arin.
rfc-ed
isc.o
ecur
acketst
pgp
tanford.e
utgers.ed
ample
info
root@
ostmaster@
ebmaster@
you
ugs@
ating@
ontact@
soft
rivacy
ervice
help
ubmit@
feste
cert
page
upport
ntivi
istser
ertific
ccoun
spm
Spam
SPAM
spam
abuse
cafee
@messagelab
@avp
kasp
winzip
winrar
pdate
irus
ahoo
buse@
sale

The email sent by W32/Evaman-F may have the following characteristics:

[Subjects]
Album
Ok, here it is...
Ok, here it is...
You'v got 1 VideoMail!
You'v got 1 VideoMail!
You'v Received a E-card! (Flash Card)
You'v Received a E-card! (Flash Card)

[Attachment filenames]
photo_album
budget_report
www.videomail-direct.com?download-video?mpg
www.flashecard.com?postcard=viewcard?3490

[Attachment extensions]

scr
scr
exe
exe
pif
pif
html.scr
html.scr

[Email body - Combinations of: ]

remember, just don't tell john or sandra about this ok?

You`ve got 1 VideoMessage from Videomail-Direct.com!

You have received a new e-card from flashecard.com!

humm sexy :) huh? heheh

To view your new video e-mail message follow the link:
http://www.videomail-direct.com.download.inbox1.php?34432Dh
or click the attached link.

To view your flash e-card follow the link:
http://www.flashecard.com.viewcard.main.ecard.php?23462Dh
or click the attached link.

later.

(Direct-VideoMail) Sign Up today and send free video e-mail messages!

With flashecard.com you can send free animated eletronic post cards!

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer