home *** CD-ROM | disk | FTP | other *** search
- Name : EM-Wurm
-
- Aliases : Anti-EuroMail-File-Virus, $a0 QuickInt Trojan
-
- Type/Size : Trojan BBS Infiltrator
-
- Clone : Not known clones yet
-
- Symptoms : A little confusing, not elucidated really
-
- Discovered : 16-07-91
-
- Way to infect: No Spreading
-
- Rating : Less Dangerous
-
- Kickstarts : Preferably 2.x, but not only maybe.
-
- Damage : Indeed dangerous for BBS equilibrists
-
- Removal : Remove the file immediately
-
- Comments : Usually the EM-Wurm trojan is embedded in downloaded
- powerpacked programmes which contains their own
- installers.
-
- QuickInt is its real name but sometimes something's
- going wrong with its work. It will then occur with
- the name $a0 and this is a variable in the
- environment Env:<dir> (RAM:Env/name)
- Liken:
-
- 1.SYS:> Echo > Env:a0 poooh
- 1.SYS:> Echo $a0
- poooh
- 1.SYS:>
-
- or the command GetEnv.
-
- Anyway, the file $a0 is protected ---- -w-d in
- c:<dir> and has always displaced the file QuickInt.
- Therefore this one shouldn't work. But, ...
-
-
-
- Damage All files in the entire directory concerned are
- overwritten.
-
- Nothing to salvage at all.
-
-
-
- Manifestation When the file is executed it will start a search for
- all divices or directories with names e.g.:
-
- EM:, EuroMail:, EuroSYS: or similar to that.
-
- When found it will overwrite the device contents
- with nonsense data. Especially the search for EM: is
- a bit tricky. ( Enquiries_of_Mine ... Root:EM )
-
- The behavior of the program is not explained in all
- details, yet, but when the Prefs:Env is copied to the
- environment during booting of system 2.x it would
- possibly be a good idea to take a look there.
- Sometimes it looks like it chucks a none-writeable
- character in the beginning of the StartUp-Sequence
- because of an empty line when edited.
-
- Take for example it is a LF ( LineFeed ). Nothing to
- see except the empty line. Watch Your StartUp's first
- calls.
-
-
-
- More comments Something gives the conjecture that the file
- originately was made to upload at a BBS. When the
- System Administrator then unpacked the file on his
- BBS the file would execute without his cooperation,
- which means, it could download something to the
- uploader, unless the System Administrator turned
- the mainpower off his machine.
-
- In this way the invisible character in the
- StartUp-Sequence probably would be a CR ( Carriage
- Return "^m" )
-
-
- TBH 04-94
-