Installation and Autostart Technique
Upon execution, this memory-resident worm drops the following copies of itself:
- %System Root%\upDate.exe
(Note: %System Root% refers to the root directory, which is usually C:\. %System% is the Windows system folder, which is usually C:\Windows\System on Windows 95, 98, and ME, C:\WINNT\System32 on Windows NT and 2000, or C:\Windows\System32 on Windows XP. %Windows% is the Windows folder, which is usually C:\Windows or C:\WINNT.)
It also drops the following .DLL files associated with WORM_LOVGATE.Q:
To ensure execution at every Windows startup, it creates the following registry entries:
WinHelp = "%System%\TkBellExe.exe"
Soft Profile Inc = "%System%\hxdef.exe"
Microsoft Inc. = "iexplorer.exe"
VFW Encoder/Decoder Settings = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg"
Program In Windows = "%System%\IEXPLORE.EXE"
Protected Storage = "RUNDLL32.EXE MSSIGN30.DLL ondll_reg"
SystemTra = "%Windows%\Video.EXE"
Installed shell32.dll = "Office.exe"
Run = "real.exe"
Run = "real.exe"
It also modifies the file association of text files (*.TXT) in the registry to execute its dropped copy every time a .TXT file is opened.
Propagation via Network Shares
This worm drops copies of itself in accessible shared folders as an executable file or as a WinRar-compressed file. It may use any of the filenames in the following partial list:
- Daemon Tools v3.41
- EnterNet 500 V1.5 RC1
- FoxMail V5.0.500.0
- Microsoft Office
- Winamp skub_FinalFantasy
- Windows Media Player.zip
- WinGate V5.0.10 Build
- WINISO 5.3
- Support Tools
- Flash2X Flash Hunter v1.1.2
- Windows 2000 sp4.ZIP
- Serv-U FTP Server 4.1
- Winamp skin_FinalFantasy
The above filenames may have any of the following filename extensions:
It may also drop copies in random folders on an infected system, using up disk space.
Propagation via Email
This worm uses its own SMTP engine to propagate via email. The email it sends out has the following details:
Subject: (any of the following)
�Delivery Status Notification (Delay)
�Mail Transaction Failed
Message body: (any of the following)
This is an automatically generated Delivery Status Notification
THIS IS A WARNING MESSAGE ONLY.
YOU DO NOT NEED TO RESEND YOUR MESSAGE.
Delivery to the following recipient has failed:
The message contains Uniocode characters and has been sent as a binary attachment.
Mail failed. For further assistance, Please contact!
It's the long-awaited film version of the Broadway hit. The message sent as a binary attachment.
Attachments (any of the following filenames)
The attachment may have any of the following filename extensions:
It may also send out email with blank subject ang message body. Additionaly, it may send a randomly named file as attachment.
This worm is compressed twice, producing two samples of different sizes. It is first compressed with PE Compact (165,888 bytes), then with Aspack (171,520 bytes).
Analysis by: Joseph Cepe