Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 24 October 2005 21:47:53 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Mircnuf-A is an IRC-worm for the Windows platform.
W32/Mircnuf-A pretends to be a serial key generator for a multiplayer online game.
When first run, W32/Mircnuf-A installs itself to <Windows>\Q4Keygen.exe.
W32/Mircnuf-A drops and executes a temporary batch file, with a random name, in the <Temp> folder.
However, a permanent copy of this batch file may be installed in the following locations, if they exist:
C:\Dokumente und Einstellungen\All Users\Startmenu\Programme\Autostart\win.bat
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\win.bat
W32/Mircnuf-A searches for IRC clients and if it recognises one, creates an initialization script with one of the following file names:
C:\mIRC\script.ini
%programfiles%\mIRC\script.ini
%programfiles%\NoNameScript\script\ownstuff.nns
%programfiles%\Gamers.IRC\bin\grc\ownscripts.grc
This script attempts to distribute W32/Mircnuf-A over IRC channels.
Sophos Anti-Virus products also detect the above batch and script files as W32/Mircnuf-A.
W32/Mircnuf-A overwrites the system file <Windows>\win.ini, destroying many initialization settings for Windows and replacing them with an entry that attempts to execute Q4Keygen.exe on startup.
In addition, the following registry entries are created to run Q4Keygen.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
\vwin
<Windows>\Q4Keygen.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
\vwin
<Windows>\Q4Keygen.exe
