Content

W32/Misodene.a@MM

Type
Virus
SubType
E-mail worm
Discovery Date
04/26/2004
Length
200,702 Bytes
Minimum DAT
4354 (04/28/2004)
Updated DAT
4354 (04/28/2004)
Minimum Engine
5.1.00
Description Added
04/27/2004
Description Modified
04/28/2004 9:48 AM (PT)
Risk Assessment
Corporate User
Low
Home User
Low

Tab Navigation

Characteristics

The following characteristics are associated to the this detection:

  • harvests email addresses from the victim machine
  • contains its own SMTP engine to construct outgoing messages
  • email arrives as an attachment

Mail Propagation

Messages are constructed using the virus' own SMTP engine. They bear the following characteristics:

From: spoofed (using harvested email addresses)
Subject: Qui sabe el Pentagono sobre usted  (What the Pentagon knows about you)

Body:

?Crees que estas a salvo del Pentagono de los E.U?
Mira estos datos y te asombraras.

Do you believe you are  safe from the  Pentagon of the E.U?
Just look  these data and you will be surprised

Password: 123

Attachment: (XLS extensions with several spaces to hide the EXE extension)

System Changes:

When executed, the following message box appears:

The following files are dropped:

 En Cuba no hay libertad de expresión  Empty file
 Michael Jackson.ppt(several spaces).exe.exe  Copy of original file
 sub.sub  Subject line of email
 att1.att1  File attachment name
 msg.msg  Email message body
 Casper9247.exe  Dropped file
 Mina4652.exe  Copy of original file
 red.mda  Empty file
 Red7324.exe  Copy of original file
 PentagonSecret.xls(several spaces).exe  Copy of original file
 SMTP.ocx  Third party SMTP utility

Symptoms

Presence of the dialogue box shown above

Method of Infection

This worm spreads by email, constructing messages using its own SMTP engine.

Removal

Detection is included in our BETA DAT files and will also be included in the next scheduled DAT release. In addition to the DAT version requirements for detection, the specified engine version (or greater) must also be used.

Additional Windows ME/XP removal considerations

Variants

Variants

    N/A

All Information

Overview -

This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.

Aliases

  • W32/Bertad.a@MM

Characteristics

Characteristics -

The following characteristics are associated to the this detection:

  • harvests email addresses from the victim machine
  • contains its own SMTP engine to construct outgoing messages
  • email arrives as an attachment

Mail Propagation

Messages are constructed using the virus' own SMTP engine. They bear the following characteristics:

From: spoofed (using harvested email addresses)
Subject: Qui sabe el Pentagono sobre usted  (What the Pentagon knows about you)

Body:

?Crees que estas a salvo del Pentagono de los E.U?
Mira estos datos y te asombraras.

Do you believe you are  safe from the  Pentagon of the E.U?
Just look  these data and you will be surprised

Password: 123

Attachment: (XLS extensions with several spaces to hide the EXE extension)

System Changes:

When executed, the following message box appears:

The following files are dropped:

 En Cuba no hay libertad de expresión  Empty file
 Michael Jackson.ppt(several spaces).exe.exe  Copy of original file
 sub.sub  Subject line of email
 att1.att1  File attachment name
 msg.msg  Email message body
 Casper9247.exe  Dropped file
 Mina4652.exe  Copy of original file
 red.mda  Empty file
 Red7324.exe  Copy of original file
 PentagonSecret.xls(several spaces).exe  Copy of original file
 SMTP.ocx  Third party SMTP utility

Symptoms

Symptoms -

Presence of the dialogue box shown above

Method of Infection

Method of Infection -

This worm spreads by email, constructing messages using its own SMTP engine.

Removal -

Removal -

Detection is included in our BETA DAT files and will also be included in the next scheduled DAT release. In addition to the DAT version requirements for detection, the specified engine version (or greater) must also be used.

Additional Windows ME/XP removal considerations

Variants

Variants -

    N/A