A low-impact e-mail worm targeting a known
vulnerability in Microsoft Windows has been detected in the wild and
online security firms are warning that the worm is capable of spreading a
variant of the active Funlove virus.
Software consultants F-Secure said the Bridex
(Braid, W32/Braid@mm, W32/Braid.A-mm, I- Worm.Bridex) worm arrives in
e-mails without a subject line and with a README.EXE attachment.
When the worm’s file is run, it copies itself as REGEDIT.EXE file to the
Windows System folder and creates a startup key for this file in the System
Registry, allowing the activation of the worm’s file every time Windows
starts, the company warned.
It then scans the victim’s Microsoft Outlook address book and e-mails copies
of itself to any addresses it finds. The Bridex worm, written in Visual
Basic, targets the IFrame exploit to run itself automatically on some
systems and creates an EML file on a desktop (like the Nimda worm does) and
also drops a bit modified Funlove
virus-worm to a system.
The IFrame vulnerability, which has since been patched by Microsoft, allows an attacker to execute script on
any page that contains frame or iframe (inline frame) elements, ignoring any
protocol or domain restriction set forth by IE.
F-Secure noted that when the FunLove virus-worm is dropped, the beginning of
MSCONFIG.EXE file is replaced with FunLove dropper meaning the file can’t be
disinfected and should be deleted and restored from a backup.
“The Funlove virus-worm first infects all EXE files on a local hard disk and
then starts to infect files on shared drives. This is a network virus-worm,
so in case of infection, a network has to be taken down before all infected
workstations are disinfected. However taking down a network is not necessary
when FSAV 5.40 is installed on every workstation. This FSAV version can
repell all attempts to infect a workstation from a network,” the company
said.
The company found that the Bridex worm also copies itself as EXPLORER.EXE to
an infected computer’s desktop. “When this file is started and the worm is
already in memory, it sometimes attempts to open a connection to
www.hotmail.com or to www.sex.com websites,” it warned.
Disinfection of the worm requires deleting of all its files including
EXPLORER.EXE and HELP.EML from a desktop and disinfecting all files from
Funlove virus infection. Funlove’s dropper BRIDE.EXE and corrupted
MSCONFIG.EXE files should be also deleted, F-Secure added.