Sophos

W32/Mircnuf-A

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Chat programs
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 24 October 2005 21:47:53 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

W32/Mircnuf-A is an IRC-worm for the Windows platform.

W32/Mircnuf-A pretends to be a serial key generator for a multiplayer online game.

When first run, W32/Mircnuf-A installs itself to <Windows>\Q4Keygen.exe.

W32/Mircnuf-A drops and executes a temporary batch file, with a random name, in the <Temp> folder.
However, a permanent copy of this batch file may be installed in the following locations, if they exist:

C:\Dokumente und Einstellungen\All Users\Startmenu\Programme\Autostart\win.bat
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\win.bat

W32/Mircnuf-A searches for IRC clients and if it recognises one, creates an initialization script with one of the following file names:

C:\mIRC\script.ini
%programfiles%\mIRC\script.ini
%programfiles%\NoNameScript\script\ownstuff.nns
%programfiles%\Gamers.IRC\bin\grc\ownscripts.grc

This script attempts to distribute W32/Mircnuf-A over IRC channels.

Sophos Anti-Virus products also detect the above batch and script files as W32/Mircnuf-A.

W32/Mircnuf-A overwrites the system file <Windows>\win.ini, destroying many initialization settings for Windows and replacing them with an entry that attempts to execute Q4Keygen.exe on startup.

In addition, the following registry entries are created to run Q4Keygen.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
\vwin
<Windows>\Q4Keygen.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
\vwin
<Windows>\Q4Keygen.exe

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer