|
|

This is only a preview of the paper Click here to register and get the full text. Existing members click here to login
|
|
|
Name: Karen
Alias: W32/Karen@mn, Gokar. ... A worm can spread itself automatically over the network from one computer to the next. ...
Karen is a combination of e-mail, IRC and IIS web worm. ...
Karen sends itself via Microsoft Outlook, using a long list of variable subject fields, contents and attachment names. ...
An infected machine can be manually detected by checking the existance of KAREN. ...
If the infected machine is working as a web server, the worm will modify the Microsoft IIS starting page to offer WEB. ...
Karen also modifies mIRC chat client configuration to spread to worm further via IRC chats.
Karen is detected by F-Secure Anti-Virus update shipped on 13th of December.
TECHNICAL INFORMATION
The worm is written in Visual Basic and has been compressed by the UPX file compressor.
The worm infects a computer when a user opens an infected attachment. The worm copies itself as KAREN. ... Then the worm creates the following key:
[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
"Karen" = "karen. ...
After that the worm opens Outlook Address book and sends itself to all e-mail addresses it can find there. ...
Speak to you later
After the body the worm puts Windows registered user name (the name of a person Windows is registered to). ... com
Heres an example of an infected message:
The worm also spreads via IRC. ... This script allows the worm to send itself as KAREN. ... The worm sends itself with the following message:
If this doesnt make you smile, nothing will.
The worm looks for specific text messages in IRC channel and can change users nickname to W32_Karen, W32Karen1, KarenWorm, KarenGobo or join #teamvirus channel on certain messages.
The worm can also spread from a webpage. ... It it is found the worm copies itself as WEB. ... If a user accepts to Run this file from current location, the worm will be downloaded and activated on his system.
The worm looks for and terminates processes belonging to anti-virus and security software.
Approximate Word count = 1589 Approximate Pages = 6.4 (250 words per page double spaced)
|
|
|
|
|
|