Content

W32/Kindal@MM

Type
Virus
SubType
E-mail
Discovery Date
03/07/2003
Length
936,111 bytes
Minimum DAT
4253 (03/19/2003)
Updated DAT
4320 (01/28/2004)
Minimum Engine
5.1.00
Description Added
03/27/2003
Description Modified
03/27/2003 5:44 PM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

This mass-mailing worm sends itself to all users found in the Windows Address Book (WAB) with a variety of possible emails:

Email #1 -
From: The SoftNet Security HQ
MailFrom: d.mike@netsecurityhq.com
Subject: Free Net Security Bullettin Service: New security hole.
Attachment: CP_2OOAF3.exe
Body:
Cumulative Patch: (CP_2OOAF3)
Priority: Medium/High
Patch availability: Win9x/NT/XP

The problems could let an attacker run code on your machine, read certain types of data files on an affected system, or misrepresent the origin of a file offered for download. Please, make sure your system is not affected by this problem by running the attached Analyzer/Patch.

Regards,
The SoftNet Security HQ.
--
Mike Donovald
Softnet Security HQ
email:

Email #2 -
From: Wine Richman
MailFrom: w.richman@itoneonline.org
Subject: Wine Richman - my updated resume.
Attachment: Wine_Richman.exe
Body:
Dear Ms. Tempton:

It was very enjoyable to speak with you tod ay about the assistant account executive position at the Smith Agency. The job seems to be an excellent match for my skills and interests. The creative approach to account management that you described confirmed my desire to work with you.

Please find my updated resume in the attachment.

Sincerely,
Wine Richman
w.richman@itoneonline.org
File: Wine_Richman.exe ( Selfextracting zip archive )

Email #3 -
From: Anne Rosoe
MailFrom: anne_resoe79@hotmail.com
Subject: Hi, news about the party !
Attachment: Party List-Anne.exe
Body:
Hi wazzzup ? As promised I'm sending you the zip with all the details about the party and the list for the things we are still missing.

Let me know what you think !
cheers Anne.

Email #4 -
From: Skid Marton [@work]
MailFrom: enemy@8mileroad.ca
Subject: I mate, there you go...
Attachment: This_Is_How_I_Feel-Track-02.remixed.exe
Body:
Lyrics below and audio track file attached. Cya !

(It's okay, it's okay. I'm gonna make it anyway.)
Sometimes I just feel, like Quittin I still might
Why do I still write?
And show these people what my level of skill's like
Sometimes I just hate life, Somethin ain't right
I'm goin the fuck home, She don't understand
Time for me to just to take matters into my own hands
Sometimes I get upset I'm just tryin to do what's best
And I try Sit alone and I cry Please I'm beggin you God
Please don't let me be pigeon holdin on regular job
Wherever you are, I'm tellin you dog

I've got every ingredient All I need is the courage
Cuz I ain't havin no luck with this so fuck it

Email #5 -
From: Stan Crossfert
MailFrom: stan.cros@NO_SPAMrabbitrun.org
Subject: Hi Marshall, here is my project for you to check...
Attachment: ProjectPlans.exe
Body:
Hey ya, check out the attached zip executable. Have a look at the whole thing, but pay attention to Fiona's plans (Folder Fiona\mywishes.txt ). She is going pretty much out of the schemes.

Ah, I forgot, how's your mum ?

______________________________

When the worm sends an email to each individual entry in the address book, it also puts in the BCC field all other email addresses in the WAB. This would mean that the email would get sent to each address as many times as there are WAB entries, plus one. This is also notable because it would expose every email address in the victim machine's WAB to every other person in that address book.

This worm has its own SMTP engine, and uses the default SMTP account information to find a server to send itself through.

The worm may also try to copy itself to shared folders for KaZaA, Overnet, LimeWire or Morpheus, but this was not observed in testing. If so, it may copy itself using the following list of filenames:

  • MyStuff Archive.exe
  • [eBook]The Hacker Zipped.exe
  • PornStar Pic.jpg.pif
  • Stacy Valentine.pif
  • Quake 3 Arena CD KeyGen.exe
  • [eBook] Sex And The City Zipped.exe
  • Warcraft 3 Crack.exe
  • [eBook] WebSite Design Zipped.exe
  • AGV Antivirus Pro.exe
  • WinZip 8.1 KeyGen.exe
  • Personal Firewall Pro.exe
  • Window Blinds + KeyGen.exe
  • Nero Burning Rom 5.5 KeyGen.exe
  • Eminem - 8 Mile Screensaver.scr
  • Adobe Photoshop 6 KeyGen.exe
  • HyperSnap-DX (Full + Crack).exe
  • Macromedia Flash MX 6.0 Crack.exe
  • SWiSH 2.0 KeyGen+Crack.exe
  • Kaspersky Anti-Virus Pro (KeyGen+Crack).exe
  • PC-Cillin 9.02 (Keygen+Crack).exe
  • GetRight 4.5e (KeyGen+Crack).exe
  • Age of Mythology (NoCD+Crack).exe
  • Easy CD Creator 5 Preview Crack.exe
  • Eminem 8 Mile Wallpaper.exe
  • WindowsXP SP KeyGen.exe
  • [eBook] The Black Art Of Hacking
  • ICQ Sniffer.exe
  • Lord Of The Rings Screensaver.scr
  • kaspersky Anti-Virus
  • Eminem Desktop.exe
  • Borland Delphi Trial Crack.exe
  • Civilization III (Latest Cracked Patch).exe
  • Old Games Collection I.exe
  • CuteFTP PRO (Serial included).exe
  • ACDSee 5.0 (Crack+Serial).exe
  • DivX Video Bundle
  • Diskeeper 7.0 (Trial Crack).exe
  • mIRC32 (Serial included).exe
  • ZoneAlarm Firewall.exe
  • Eminem 8 Mile Censored Scene.exe
  • Personal Web Server.exe
  • Paint Shop Pro 7 Crack.exe
  • Winzip 8.1 Full.exe
  • The Eminem Show (Full Album).exe
  • Porn Games Collection I.exe
  • MAME ROMS Archive I.exe
  • MAME ROMS Archive II.exe
  • Final Fantasy ROM collection I.exe
  • Nintendo64 Emulator (ROM included).exe
  • Castle Wolfstein Multiplayer KeyGen.exe
  • The Sims Online Crack.exe
  • The Sims Nude Patch.exe
  • XCOM 3 Apocalypse.exe
  • Leisure Suit Larry 6.exe
  • Virtual Valerie 2.exe
  • Queens Of The Stone Age (Complete Album).exe
  • DivX Codecs Pack (All Needed codecs).exe
  • Strip Poker 3.exe
  • Britney Spear (Nude Pics Pack).exe
  • Hacker Tools Pack.exe
  • [eBook] Visual Basic Programming Handlebook.exe
  • WinXP Themes Pack.exe
  • Unreal 2 0][0 3 (Official Crack).exe
  • Doom 3 Leaked Beta.exe
  • Lula The Sexy Empire (Full+Crack).exe
  • Paint Shop Pro7 KeyGen.exe

    The filenames and email information are all encrypted, so they are not visible within the executable.

    When run, the worm copies itself locally:

  • %WinDir%\systask32l.exe
  • %SysDir%\ln32k.exe

    It also creates an empty, hidden folder:

  • %SysDir%\kindlyback

    It creates a file which contains system date from when the file was run:

  • %SysDir%\ln32k.DLL

    The worm creates the following registry entries so it will run again on system startup:

  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    "SysService32" = %WinDir%\systask32l.exe

  • Symptoms

  • Presence of the files, folders and registry entries listed above
  • Unexpected SMTP traffic
  • Method of Infection

    The virus spreads via mailing itself to any user found in the Windows Address Book contact list and copying itself to the P2P clients' shared folder, upon execution.

    Removal

    All Users:
    Use current engine and DAT files for detection and removal.

    Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

    Additional Windows ME/XP removal considerations

    Variants

    Variants

      N/A

    All Information

    Overview -

    This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

    Aliases

    • I-Worm.Kindal (AVP)
    • W32.HLLP.Kindal@mm (NAV)
    • W32/Kindal (Panda)

    Characteristics

    Characteristics -

    This mass-mailing worm sends itself to all users found in the Windows Address Book (WAB) with a variety of possible emails:

    Email #1 -
    From: The SoftNet Security HQ
    MailFrom: d.mike@netsecurityhq.com
    Subject: Free Net Security Bullettin Service: New security hole.
    Attachment: CP_2OOAF3.exe
    Body:
    Cumulative Patch: (CP_2OOAF3)
    Priority: Medium/High
    Patch availability: Win9x/NT/XP

    The problems could let an attacker run code on your machine, read certain types of data files on an affected system, or misrepresent the origin of a file offered for download. Please, make sure your system is not affected by this problem by running the attached Analyzer/Patch.

    Regards,
    The SoftNet Security HQ.
    --
    Mike Donovald
    Softnet Security HQ
    email:

    Email #2 -
    From: Wine Richman
    MailFrom: w.richman@itoneonline.org
    Subject: Wine Richman - my updated resume.
    Attachment: Wine_Richman.exe
    Body:
    Dear Ms. Tempton:

    It was very enjoyable to speak with you tod ay about the assistant account executive position at the Smith Agency. The job seems to be an excellent match for my skills and interests. The creative approach to account management that you described confirmed my desire to work with you.

    Please find my updated resume in the attachment.

    Sincerely,
    Wine Richman
    w.richman@itoneonline.org
    File: Wine_Richman.exe ( Selfextracting zip archive )

    Email #3 -
    From: Anne Rosoe
    MailFrom: anne_resoe79@hotmail.com
    Subject: Hi, news about the party !
    Attachment: Party List-Anne.exe
    Body:
    Hi wazzzup ? As promised I'm sending you the zip with all the details about the party and the list for the things we are still missing.

    Let me know what you think !
    cheers Anne.

    Email #4 -
    From: Skid Marton [@work]
    MailFrom: enemy@8mileroad.ca
    Subject: I mate, there you go...
    Attachment: This_Is_How_I_Feel-Track-02.remixed.exe
    Body:
    Lyrics below and audio track file attached. Cya !

    (It's okay, it's okay. I'm gonna make it anyway.)
    Sometimes I just feel, like Quittin I still might
    Why do I still write?
    And show these people what my level of skill's like
    Sometimes I just hate life, Somethin ain't right
    I'm goin the fuck home, She don't understand
    Time for me to just to take matters into my own hands
    Sometimes I get upset I'm just tryin to do what's best
    And I try Sit alone and I cry Please I'm beggin you God
    Please don't let me be pigeon holdin on regular job
    Wherever you are, I'm tellin you dog

    I've got every ingredient All I need is the courage
    Cuz I ain't havin no luck with this so fuck it

    Email #5 -
    From: Stan Crossfert
    MailFrom: stan.cros@NO_SPAMrabbitrun.org
    Subject: Hi Marshall, here is my project for you to check...
    Attachment: ProjectPlans.exe
    Body:
    Hey ya, check out the attached zip executable. Have a look at the whole thing, but pay attention to Fiona's plans (Folder Fiona\mywishes.txt ). She is going pretty much out of the schemes.

    Ah, I forgot, how's your mum ?

    ______________________________

    When the worm sends an email to each individual entry in the address book, it also puts in the BCC field all other email addresses in the WAB. This would mean that the email would get sent to each address as many times as there are WAB entries, plus one. This is also notable because it would expose every email address in the victim machine's WAB to every other person in that address book.

    This worm has its own SMTP engine, and uses the default SMTP account information to find a server to send itself through.

    The worm may also try to copy itself to shared folders for KaZaA, Overnet, LimeWire or Morpheus, but this was not observed in testing. If so, it may copy itself using the following list of filenames:

  • MyStuff Archive.exe
  • [eBook]The Hacker Zipped.exe
  • PornStar Pic.jpg.pif
  • Stacy Valentine.pif
  • Quake 3 Arena CD KeyGen.exe
  • [eBook] Sex And The City Zipped.exe
  • Warcraft 3 Crack.exe
  • [eBook] WebSite Design Zipped.exe
  • AGV Antivirus Pro.exe
  • WinZip 8.1 KeyGen.exe
  • Personal Firewall Pro.exe
  • Window Blinds + KeyGen.exe
  • Nero Burning Rom 5.5 KeyGen.exe
  • Eminem - 8 Mile Screensaver.scr
  • Adobe Photoshop 6 KeyGen.exe
  • HyperSnap-DX (Full + Crack).exe
  • Macromedia Flash MX 6.0 Crack.exe
  • SWiSH 2.0 KeyGen+Crack.exe
  • Kaspersky Anti-Virus Pro (KeyGen+Crack).exe
  • PC-Cillin 9.02 (Keygen+Crack).exe
  • GetRight 4.5e (KeyGen+Crack).exe
  • Age of Mythology (NoCD+Crack).exe
  • Easy CD Creator 5 Preview Crack.exe
  • Eminem 8 Mile Wallpaper.exe
  • WindowsXP SP KeyGen.exe
  • [eBook] The Black Art Of Hacking
  • ICQ Sniffer.exe
  • Lord Of The Rings Screensaver.scr
  • kaspersky Anti-Virus
  • Eminem Desktop.exe
  • Borland Delphi Trial Crack.exe
  • Civilization III (Latest Cracked Patch).exe
  • Old Games Collection I.exe
  • CuteFTP PRO (Serial included).exe
  • ACDSee 5.0 (Crack+Serial).exe
  • DivX Video Bundle
  • Diskeeper 7.0 (Trial Crack).exe
  • mIRC32 (Serial included).exe
  • ZoneAlarm Firewall.exe
  • Eminem 8 Mile Censored Scene.exe
  • Personal Web Server.exe
  • Paint Shop Pro 7 Crack.exe
  • Winzip 8.1 Full.exe
  • The Eminem Show (Full Album).exe
  • Porn Games Collection I.exe
  • MAME ROMS Archive I.exe
  • MAME ROMS Archive II.exe
  • Final Fantasy ROM collection I.exe
  • Nintendo64 Emulator (ROM included).exe
  • Castle Wolfstein Multiplayer KeyGen.exe
  • The Sims Online Crack.exe
  • The Sims Nude Patch.exe
  • XCOM 3 Apocalypse.exe
  • Leisure Suit Larry 6.exe
  • Virtual Valerie 2.exe
  • Queens Of The Stone Age (Complete Album).exe
  • DivX Codecs Pack (All Needed codecs).exe
  • Strip Poker 3.exe
  • Britney Spear (Nude Pics Pack).exe
  • Hacker Tools Pack.exe
  • [eBook] Visual Basic Programming Handlebook.exe
  • WinXP Themes Pack.exe
  • Unreal 2 0][0 3 (Official Crack).exe
  • Doom 3 Leaked Beta.exe
  • Lula The Sexy Empire (Full+Crack).exe
  • Paint Shop Pro7 KeyGen.exe

    The filenames and email information are all encrypted, so they are not visible within the executable.

    When run, the worm copies itself locally:

  • %WinDir%\systask32l.exe
  • %SysDir%\ln32k.exe

    It also creates an empty, hidden folder:

  • %SysDir%\kindlyback

    It creates a file which contains system date from when the file was run:

  • %SysDir%\ln32k.DLL

    The worm creates the following registry entries so it will run again on system startup:

  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    "SysService32" = %WinDir%\systask32l.exe

  • Symptoms

    Symptoms -

  • Presence of the files, folders and registry entries listed above
  • Unexpected SMTP traffic
  • Method of Infection

    Method of Infection -

    The virus spreads via mailing itself to any user found in the Windows Address Book contact list and copying itself to the P2P clients' shared folder, upon execution.

    Removal -

    Removal -

    All Users:
    Use current engine and DAT files for detection and removal.

    Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).

    Additional Windows ME/XP removal considerations

    Variants

    Variants -

      N/A