Sophos

W32/Marijuana

Aliases
  • I-Worm.Mari
  • W32/Mari
Category
Type
What to do
Prevalence low high

Summary

 
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Marijuana is a worm that attempts to email itself to entries in the Microsoft Outlook address book with the subject "check this out!!!". The worm copies itself to system32.exe in the Windows directory, and sets the registry key HKLM\Software\Microsoft\Windows
\CurrentVersion\Run\System32
to point to the copy, so that it runs on every reboot.

The worm sets the Internet Explorer home page to http://my.marijuana.com and changes the Windows registered owner to "Im A Pot Head!", and the organisation to "Stoner's Pot Palace".

It puts an icon of a marijuana leaf in the system tray.

Marijuana leaf icon

When the user clicks on the icon, it displays a message box with a long statement about legalising marijuana.

Legalise marijuana message box

Each day at 16:20, it displays a message box with the title "The Marijuana Virus!!" and the message "It's 4:20, Time to toke up :)"

'Time to toke up' message box

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer