Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Included in our products from | June 2006 (4.06) |
| Protection available since | 10 October 2005 12:59:41 (GMT) |
| Last updated | 11 May 2006 07:29:08 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Windows NT/2000/XP/2003
In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Zi5
<System>\AntiVirus Update.exe
and delete it if it exists.
Close the registry editor.
More Information
W32/Erkez-G is an email and peer-to-peer worm for the Windows platform.
W32/Erkez-G sends emails in the following format, where the subject and message are chosen depending upon the email address the worm is being sent to:
Subject:
msn photo ecard,commercial ecard :))
broma :)),humor :))
rolig reklam :)),haha - rolig :))
witzig reklame :)),witzig bild :D
grappig beeld :)),een grappig reclame :D
blague :)),humour - reclame :))
cherzo :)),comico quadro :))
Message:
ImageFormat: <Size>
ImageSize: <Size Kb>
Message: you need to see this :))
From: <Name>
Date: <Date sent>
AV-Control: <Filename>
Cuadro/Format: <Size>
Cuadro/Medida: <Size Kb>
Mensaje: Sexo y humor para pasar un buen rato! :))
Expedidor: <Name>
Data: <Date sent>
Control: <Filename>
Bildform: <Size>
Bild/Omfattning: <Size Kb>
Meddelande: rolig reklam!! :))
Post: <Name>
Datum: <Date sent>
Control: <Filename>
BildFormat: <Size>
Bildabmessung: <Size Kb>
Botschaft: eine witzig reklame foto :))
Absender: <Name>
Datum: <Date sent>
Kontrolle: <Filename>
Beeldformaat: <Size>
Beeldmaat: <Size Kb>
Boodschap: een ontroerend of grappig reclame :))
Afzender: <Name>
Datum: <Date sent>
Controle: <Filename>
Image/Mode: <Size>
Image/Taille: <Size Kb>
Message: le sexe d'une femme apres l'amour (humour, reclame) :))
Expediteur: <Name>
Date: <Date sent>
Verification: <Filename>
Quadro/Forma: <Size>
Quadro/Proporzioni: <Size Kb>
Messaggio: comico reclame!! :))
Mittente: <Name>
Data: <Date sent>
Controllare: <Filename>
Attachment:
The attachment name will be created using the following words, with a .zip file extension:
msn
messenger
commercial
reclame
reklame
reklam
humor
megasztar
humor
photo
pict
imag
dscn
W32/Erkez-G is an email and peer-to-peer worm for the Windows platform.
When first run W32/Erkez-G copies itself to any folders it finds containg the words "musi", "shar", or "uploa" with a name of either "Adobe Acrobat 8.0 Pro.exe" or "Windows Update Crack.exe", as well as to the following locations:
<System>\AntiVirus Update.exe
<System>\antivirus_update.exe
<System>\foto5.jpz
The following registry entry is created to run "AntiVirus Update.exe" on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Zi5
<System>\AntiVirus Update.exe
The worm also creates several files in the Windows system folder with names of the format <8 random letters>.dll. Most of these are clean data files, and contain logged email details. Some may be copies of the worm.
The worm searches for email addresses in files with the following file extenstions:
dbx
asp
txt
htm
mbx
wab
php
sht
adb
tbb
inb
pmr
fpt
eml
W32/Erkez-G sends emails in the following format, where the subject and message are chosen depending upon the email address the worm is being sent to:
Subject:
msn photo ecard,commercial ecard :))
broma :)),humor :))
rolig reklam :)),haha - rolig :))
witzig reklame :)),witzig bild :D
grappig beeld :)),een grappig reclame :D
blague :)),humour - reclame :))
cherzo :)),comico quadro :))
Message:
ImageFormat: <Size>
ImageSize: <Size Kb>
Message: you need to see this :))
From: <Name>
Date: <Date sent>
AV-Control: <Filename>
Cuadro/Format: <Size>
Cuadro/Medida: <Size Kb>
Mensaje: Sexo y humor para pasar un buen rato! :))
Expedidor: <Name>
Data: <Date sent>
Control: <Filename>
Bildform: <Size>
Bild/Omfattning: <Size Kb>
Meddelande: rolig reklam!! :))
Post: <Name>
Datum: <Date sent>
Control: <Filename>
BildFormat: <Size>
Bildabmessung: <Size Kb>
Botschaft: eine witzig reklame foto :))
Absender: <Name>
Datum: <Date sent>
Kontrolle: <Filename>
Beeldformaat: <Size>
Beeldmaat: <Size Kb>
Boodschap: een ontroerend of grappig reclame :))
Afzender: <Name>
Datum: <Date sent>
Controle: <Filename>
Image/Mode: <Size>
Image/Taille: <Size Kb>
Message: le sexe d'une femme apres l'amour (humour, reclame) :))
Expediteur: <Name>
Date: <Date sent>
Verification: <Filename>
Quadro/Forma: <Size>
Quadro/Proporzioni: <Size Kb>
Messaggio: comico reclame!! :))
Mittente: <Name>
Data: <Date sent>
Controllare: <Filename>
Attachment:
The attachment name will be created using the following words, with a .zip file extension:
msn
messenger
commercial
reclame
reklame
reklam
humor
megasztar
humor
photo
pict
imag
dscn
Registry entries are created under the following branch:
HKLM\SOFTWARE\Microsoft\Zi5
The entries under this branch will locate the data and worm files with the .dll extension.
The following files are also created:
<System>\a.wsf
C:\z.m
C:\m
These are clean data files, and may safely be deleted.
