This worm is a proof-of-concept malicious program. It demonstrates how a game construction kit program, such as Game Maker, can be utilized maliciously.
A game construction kit is good enough to create 2D computer games which can run in Windows platforms. It supports functions (or scripts) that can execute when an event is triggered. Some of its functions allow a malicious game programmer to do the following:
- Manipulate the system registry and files and folders in the affected system.
- Execute any program in the system.
It gives the malicious programmer the option to compile and produce Win32 executable (.EXE) files.
TrendLabs would like to emphasize that it does not consider and detect the game construction program per se as a malicious program. However, with its features and capabilities, it can be used maliciously.
Arrival and Installation
This worm arrives as a file downloaded via Kazaa.
When executed, this worm checks for the presence of the folder C:\Windows. It then attempts to drop a copy of itself into the folder as microsoftscanreg.exe.
If it successfully drops the copy, this worm plays a MIDI audio tune and then displays the following message:
It displays this message if it encounters an error:
This worm adds the following registry entry so that it executes every time Windows starts:
Microsoft Scanreg = "C:\Windows\microsoftscanreg.exe"
This worm creates the following subfolder in the C:\Windows:
\scanregfile\kazaa\My Shared Folder
It then drops copies of itself using the following file names into the newly created folder:
- Age Of Mythology FR CRACK.exe
- Alcatraz Fr Crack.exe
- Allopass %20 audiotel Keygen 2003.exe
- Arx Fatalis FR CRACK.exe
- Battlefield 1942 FR Crack.exe
- Clone CD 5 keygen.exe
- Delphi 5 fr crack keygen.exe
- Delphi 6 fr crack keygen.exe
- Delphi 7 fr crack keygen.exe
- Dreamweaver MX keygen %20 crack by orran.exe
- Fire-Works MX keygen %20 crack by orran.exe
- Flash MX keygen %20 crack by orran.exe
- Madden NFL 2003 FR CRACK.exe
- Mafia Fr Nocd.exe
- Medieval Total War Fr Crack.exe
- Mega-Serial Microsoft Macromedia Borland Photoshop.exe
- Nero FR 5.6 keygen %20 crack.exe
- No One Lives Forever 2 FR CRACK.exe
- Office XP fr Activation crack keygen.exe
- Photoshop FR 7 keygen %20 crack by orran.exe
- Sim City 4 FR Crack by zorio.exe
- Unreal 2003 Fr Nocd.exe
- Visual Basic fr 6.00 crack keygen.exe
- Visual fr c%20%20 crack keygen.exe
- Visual.net fr Activation keygen crack.exe
- Winace fr 4 keygen crack.exe
- Windows XP Activation fr home Pro keygen 2003.exe
- Windows XP fr home et pro SP1 crack.exe
- Winrar fr 3.X keygen.exe
- Winzip fr 8.X keygen crack.exe
It shares the created folder in Kazaa, making the dropped copies available for download by Kazaa users. It does this by creating or modifying the following registry entry as such:
DownloadDir = "C:\Windows\scanregfile\kazaa\My Shared Folder"
Note that the described registry entry is also reflected under the key HKEY_USERS\.DEFAULT.
The worm contains bugs that may hinder it from running accordingly.
Analysis by: Rex Plantado