Content
W32/Hunch.a@MM
- Type
- Virus
- SubType
- Win32
- Discovery Date
- 01/28/2002
- Length
- 151,552 bytes
- Minimum DAT
- 4184 (01/30/2002)
- Updated DAT
- 4241 (01/08/2003)
- Minimum Engine
- 5.1.00
- Description Added
- 01/28/2002
- Description Modified
- 04/08/2002 10:48 AM (PT)
Tab Navigation
Characteristics
This threat is detected with the 4140 DATs (or higher) as New Backdoor or New Worm, when scanning with program heuristics enabled.
This mass-mailing worm sends itself to all addresses found in the Microsoft Outlook Address book, copies itself to floppy diskettes, and deletes files on the local system. It arrives in an email message containing the following information:
Subject: FileName of the executable (varies).
Body: Mensaje importante para (recipient's name) en el archivo adjunto...
Attachment: Infected executable (varies).EXE
Running the attachment infects the local machine. A window containing an image is displayed.
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run\THWIN=C:\WINDOWS\SYSTEM\THWIN.EXE - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices\THWIN=C:\WINDOWS\SYSTEM\THWIN.EXE
- BAK
- BMP
- CDX
- CHM
- DBF
- DOC
- DWG
- GIF
- HLP
- HTM
- ICO
- JPG
- MDB
- MID
- MP3
- SCR
- TTF
- WAV
- XLS
The virus attempts to overwrite the AUTOEXEC.BAT file with the following instructions:
@echo off
DEL > FORMAT C: /u /v:UNSCH /autotest
Actions performed by the worm are written to 2 files in the WINDOWS SYSTEM directory.
- ListWin.txt (a log file of the last 5 files that the virus deleted)
- WinList.txt (a log file of the filenames that the virus used to copy itself to the A: drive with)
Symptoms
Presence of the following files in the WINDOWS SYSTEM directory.
Method of Infection
Executing this virus causes it to send itself to all users found in the Microsoft Outlook Address book and to the A: drive. Files in the WINDOWS directory and subdirectories are deleted.
Removal
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Variants
Variants
N/A
All Information
Overview -
This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
Aliases
- I-Worm.Hunch (AVP)
- W32.Hunch@mm (NAV)
- W32/Hunch (Panda)
- W32/Hunch.b@MM
- W32/Hunch@MM
- Win32.Hunch (CA)
- Worm/Hunch.B (AVX)
- WORM_HUNCH.A (Trend)
Characteristics
Characteristics -
This threat is detected with the 4140 DATs (or higher) as New Backdoor or New Worm, when scanning with program heuristics enabled.
This mass-mailing worm sends itself to all addresses found in the Microsoft Outlook Address book, copies itself to floppy diskettes, and deletes files on the local system. It arrives in an email message containing the following information:
Subject: FileName of the executable (varies).
Body: Mensaje importante para (recipient's name) en el archivo adjunto...
Attachment: Infected executable (varies).EXE
Running the attachment infects the local machine. A window containing an image is displayed.
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run\THWIN=C:\WINDOWS\SYSTEM\THWIN.EXE - HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
RunServices\THWIN=C:\WINDOWS\SYSTEM\THWIN.EXE
- BAK
- BMP
- CDX
- CHM
- DBF
- DOC
- DWG
- GIF
- HLP
- HTM
- ICO
- JPG
- MDB
- MID
- MP3
- SCR
- TTF
- WAV
- XLS
The virus attempts to overwrite the AUTOEXEC.BAT file with the following instructions:
@echo off
DEL > FORMAT C: /u /v:UNSCH /autotest
Actions performed by the worm are written to 2 files in the WINDOWS SYSTEM directory.
- ListWin.txt (a log file of the last 5 files that the virus deleted)
- WinList.txt (a log file of the filenames that the virus used to copy itself to the A: drive with)
Symptoms
Symptoms -
Presence of the following files in the WINDOWS SYSTEM directory.
Method of Infection
Method of Infection -
Executing this virus causes it to send itself to all users found in the Microsoft Outlook Address book and to the A: drive. Files in the WINDOWS directory and subdirectories are deleted.
Removal -
Removal -
All Users:
Use current engine and DAT files for detection and removal.
Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).
Additional Windows ME/XP removal considerations
Variants
Variants -
N/A