home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
System Booster
/
System Booster.iso
/
Virushunter
/
VIB
/
Virus
/
E
/
EM-Wurm
< prev
next >
Wrap
Text File
|
1996-09-26
|
3KB
|
90 lines
Name : EM-Wurm
Aliases : Anti-EuroMail-File-Virus, $a0 QuickInt Trojan
Type/Size : Trojan BBS Infiltrator
Clone : Not known clones yet
Symptoms : A little confusing, not elucidated really
Discovered : 16-07-91
Way to infect: No Spreading
Rating : Less Dangerous
Kickstarts : Preferably 2.x, but not only maybe.
Damage : Indeed dangerous for BBS equilibrists
Removal : Remove the file immediately
Comments : Usually the EM-Wurm trojan is embedded in downloaded
powerpacked programmes which contains their own
installers.
QuickInt is its real name but sometimes something's
going wrong with its work. It will then occur with
the name $a0 and this is a variable in the
environment Env:<dir> (RAM:Env/name)
Liken:
1.SYS:> Echo > Env:a0 poooh
1.SYS:> Echo $a0
poooh
1.SYS:>
or the command GetEnv.
Anyway, the file $a0 is protected ---- -w-d in
c:<dir> and has always displaced the file QuickInt.
Therefore this one shouldn't work. But, ...
Damage All files in the entire directory concerned are
overwritten.
Nothing to salvage at all.
Manifestation When the file is executed it will start a search for
all divices or directories with names e.g.:
EM:, EuroMail:, EuroSYS: or similar to that.
When found it will overwrite the device contents
with nonsense data. Especially the search for EM: is
a bit tricky. ( Enquiries_of_Mine ... Root:EM )
The behavior of the program is not explained in all
details, yet, but when the Prefs:Env is copied to the
environment during booting of system 2.x it would
possibly be a good idea to take a look there.
Sometimes it looks like it chucks a none-writeable
character in the beginning of the StartUp-Sequence
because of an empty line when edited.
Take for example it is a LF ( LineFeed ). Nothing to
see except the empty line. Watch Your StartUp's first
calls.
More comments Something gives the conjecture that the file
originately was made to upload at a BBS. When the
System Administrator then unpacked the file on his
BBS the file would execute without his cooperation,
which means, it could download something to the
uploader, unless the System Administrator turned
the mainpower off his machine.
In this way the invisible character in the
StartUp-Sequence probably would be a CR ( Carriage
Return "^m" )
TBH 04-94