Content
W32/Sory.worm
- Type
- Virus
- SubType
- Worm
- Discovery Date
- 04/25/2003
- Length
- 232,960 bytes
- Minimum DAT
- 4260 (04/30/2003)
- Updated DAT
- 4260 (04/30/2003)
- Minimum Engine
- 5.1.00
- Description Added
- 04/28/2003
- Description Modified
- 04/28/2003 12:29 PM (PT)
Tab Navigation
Characteristics
This is a share-jumping worm (copies itself from system to system through Windows file-sharing functionality) that spreads to Win2K/XP systems. It also captures system and personal information. The worm does not spread via email. When run, the worm copies itself to the WINDOWS SYSTEM (%SysDir%) directory as Services.exe and creates a registry run key to load itself at system startup.
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run "Services" = %VirusPath%
- win.ini, [windows] "load" = %VirusPath%
- win.ini, [windows] "run" = %VirusPath%
- system.ini, [boot] "shell" = Explorer.exe %VirusPath%
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\
Windows "run" = %VirusPath% - HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\
Winlogon "shell" = Explorer.exe %VirusPath% - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "Services" = %VirusPath%
- Documents and Settings\All Users\Start Menu\Programlar\BASLANGIÇ\ (Turkey start menu)
- Documents and Settings\All Users\Start Menu\Programs\Startup
- Windows version
- Number, type, and speed of CPUs
- Amount of RAM
- Size of Page File
- Victim's default SMTP server, POP3 Server, POP3 username, and email address (specified in the victim's registry Internet Account Manager settings)
Symptoms
Presence of a file named services.exe (232,960 bytes) in the SYSTEM directory
Method of Infection
This worm spreads by copying itself to the STARTUP folder of accessible networked Win2K/XP systems.
Removal
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Aliases
- TROJ_TAMPONAI.A (Trend)
- W32.HLLW.Kullan (Symantec)
Characteristics
Characteristics -
This is a share-jumping worm (copies itself from system to system through Windows file-sharing functionality) that spreads to Win2K/XP systems. It also captures system and personal information. The worm does not spread via email. When run, the worm copies itself to the WINDOWS SYSTEM (%SysDir%) directory as Services.exe and creates a registry run key to load itself at system startup.
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run "Services" = %VirusPath%
- win.ini, [windows] "load" = %VirusPath%
- win.ini, [windows] "run" = %VirusPath%
- system.ini, [boot] "shell" = Explorer.exe %VirusPath%
- HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\
Windows "run" = %VirusPath% - HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\
Winlogon "shell" = Explorer.exe %VirusPath% - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Run "Services" = %VirusPath%
- Documents and Settings\All Users\Start Menu\Programlar\BASLANGIÇ\ (Turkey start menu)
- Documents and Settings\All Users\Start Menu\Programs\Startup
- Windows version
- Number, type, and speed of CPUs
- Amount of RAM
- Size of Page File
- Victim's default SMTP server, POP3 Server, POP3 username, and email address (specified in the victim's registry Internet Account Manager settings)
Symptoms
Symptoms -
Presence of a file named services.exe (232,960 bytes) in the SYSTEM directory
Method of Infection
Method of Infection -
This worm spreads by copying itself to the STARTUP folder of accessible networked Win2K/XP systems.
Removal -
Removal -
All Users:
Use specified engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A