Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 30 September 2004 11:15:00 (GMT) |
| Last updated | 12 October 2004 19:42:14 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Evaman-F is an email worm for the Windows platform.
When first run, W32/Evaman-F copies itself to the Windows system folder with the filename syshost.exe. In order to run on system start, the worm creates the following registry entries:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
MS Update = C:\WINDOWS\System32\syshost.exe
W32/Evaman-F harvests email addresses from files on the infected machines which have file extensions contained within any of the following strings:
txt
htmb
htmlb
shtl
phpq
emll
msgq
aspd
dbxn
tbbg
adbh
pl
wab
The worm avoids sending itself to any email addresses containing the following:
icrosof
syma
msn
hotmail
anda
opho
borlan
npris
xample
mydom
@domai
ruslis
.gov
.gov
.mil
@foo
berkeley
unix
math
bsd
mit.e
gnu
fsf.
ibm
oogle
kernel
linux
fido
senet
@iana
ripe
isi.e
arin.
rfc-ed
isc.o
ecur
acketst
pgp
tanford.e
utgers.ed
ample
info
root@
ostmaster@
ebmaster@
you
ugs@
ating@
ontact@
soft
rivacy
ervice
help
ubmit@
feste
cert
page
upport
ntivi
istser
ertific
ccoun
spm
Spam
SPAM
spam
abuse
cafee
@messagelab
@avp
kasp
winzip
winrar
pdate
irus
ahoo
buse@
sale
The email sent by W32/Evaman-F may have the following characteristics:
[Subjects]
Album
Ok, here it is...
Ok, here it is...
You'v got 1 VideoMail!
You'v got 1 VideoMail!
You'v Received a E-card! (Flash Card)
You'v Received a E-card! (Flash Card)
[Attachment filenames]
photo_album
budget_report
www.videomail-direct.com?download-video?mpg
www.flashecard.com?postcard=viewcard?3490
[Attachment extensions]
scr
scr
exe
exe
pif
pif
html.scr
html.scr
[Email body - Combinations of: ]
remember, just don't tell john or sandra about this ok?
You`ve got 1 VideoMessage from Videomail-Direct.com!
You have received a new e-card from flashecard.com!
humm sexy :) huh? heheh
To view your new video e-mail message follow the link:
http://www.videomail-direct.com.download.inbox1.php?34432Dh
or click the attached link.
To view your flash e-card follow the link:
http://www.flashecard.com.viewcard.main.ecard.php?23462Dh
or click the attached link.
later.
(Direct-VideoMail) Sign Up today and send free video e-mail messages!
With flashecard.com you can send free animated eletronic post cards!
