wipe-deletion-erasure-purge


I-Worm.Skybag.a

I-Worm.Skybag.a

CyberScrub AntiVirus
Research Bank

This worm spreads via the Internet as an attachment to infected messages, and via local and file sharing networks. The worm sends itself to email addresses harvested from the infected machine.

The worm itself is a Windows PE EXE file approximately 205 KB in size.

Installation

When installing, the worm copies itself to the Windows system directory as:

bloodred.exe
Windows_kernel32.exe 

It also creates the following files in the Windows system directory:

base64exe.sys
base64zip.sys
frun.txt

The worm creates a file called 'bloodred.zip' in the Windows root directory.

Skybag then registers itself in the system registry:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
 "Microsoft Kernel"="%System%\Windows_kernel32.exe"

This ensures that the worm will be launched each time the system is rebooted.

Skybag then displays the following dialogue box:

'Windows encountered an error reading the file'
Propagation via email

The worm sends itself to all email addresses harvested from the victim computer. The worm looks for email addresses in Outlook Address Book and in files with the following extensions:

adb
asp
dbx
doc
htm
html
jsp
rtf
txt
xml

The worm uses the recipient's SMTP server to send messages to all harvested addresses.

Messages are not sent to addresses which contain the following text strings:

@avp
@fsecure
@hotmail
@microsoft
@mm
@msn
@noreply
@norman
@norton
@panda
@sopho
@symantec
@virusli
Infected messages: Sender's address (chosen at random from the list below):
administration@ 
management@ 
Server@ 
service@ 
userhelp@
Subject (chosen at random from the list below):
Detailed Information
Email Account Information
Server Error
URGENT PLEASE READ!
Urgent Update!
User Info
User Information
Message body (chosen at random from the list below):

Our server is experiencing some latency in our email service.
The attachment contains details on how your account will be affected.

Due to recent internet attacks, your Email account security is being upgraded. The attachment contains more details

Our Email system has received reports of your account flooding email servers. There is more information on this matter in the attachment

We regret to inform you that your account has been hijacked and used for illegal purposes. The attachment has more information about what has happened.

Your Email account information has been removed from the system due to inactivity. To renew your account information refer to the attachment

There is urgent information in the attachment regarding your Email account

Attachment name (chosen at random from the list below):
Account_Information
Details
Gift
Information
Update
Word_Document

with one of the following extensions:

.cmd 
.pif 
.scr 
.zip

Propagation via local and file-sharing networks

The worm searches the computer for folders where the name contains the word 'Share' and copies itself several times to each folder found, under the following names:

ACDSEE10.exe
Adobe Photoshop Full Version.exe
Battlefield 1942.exe
Brianna banks and jenna jameson.mpeg ..exe
Britney spears naked.jpeg .exe
Cisco source code.zip ..exe
DVD Xcopy xpress.exe
jenna jameson screensaver.scr
Kazaa Lite.zip ..exe
NETSKY SOURCE CODE.zip ..exe
Norton AntiVirus 2004.exe
Opera Registered version.exe
Snood new version.exe
Teen Porn.mpeg ..exe
Visual Studio.NET.zip .exe
WinAmp 6.exe
Windows crack.zip ..exe
Windows Longhorn Beta.exe
WINDOWS SOURCE CODE.zip ..exe
WinRAR.exe
Payload

Skybag.a closes the Windows Task Manager application, if it is open.

The worm overwrites the %System%\DRIVERS\ETC\HOSTS file with the following text:

127.0.0.1 www.norton.com 
127.0.0.1 norton.com 
127.0.0.1 yahoo.com 
127.0.0.1 www.yahoo.com 
127.0.0.1 microsoft.com 
127.0.0.1 www.microsoft.com 
127.0.0.1 windowsupdate.com 
127.0.0.1 www.windowsupdate.com 
127.0.0.1 www.mcafee.com 
127.0.0.1 mcafee.com 
127.0.0.1 www.nai.com 
127.0.0.1 nai.com 
127.0.0.1 www.ca.com 
127.0.0.1 ca.com 
127.0.0.1 liveupdate.symantec.com 
127.0.0.1 www.sophos.com 
127.0.0.1 www.google.com 
127.0.0.1 google.com

If the infected computer's system date is November 15, 2004 or later, the worm attempts to conduct DoS attacks against www.kazaa.com

Also the worm attempts to block the work of a number of firewalls and antivirus monitors.

I-Worm.Skybag.a opens and then monitors TCP port 2345 to listen for commands.

Check out if we have free removal tool for this virus


CyberScrub AntiVirus provides state of the art security protection for five years- at one low price. Our award winning technology ensures protection against viruses, worms and trojans backed by top customer support and value.

 
Five Year Cost Comparison
Product Initial Cost Yearly Subscription X Four Years Total
Norton 2004 AntiVirus $49.95* $29.95 $119.80 $169.75
McAfee VirusScan $49.95* $19.95 $79.80 $129.75
CyberScrub AntiVirus $49.95 Included No Additional Cost $49.95
*All prices MSRP as published on respective sites.




It is only a matter of time before a virus, worm or Trojan horse wrecks havoc on your important data. Important files, records, family pictures- all at risk. Some dangerous programs can even ruin your hard drive beyond repair.

CyberScrub AntiVirus offers the most effective protection from all known and unknown viruses.

CyberScrub AntiVirus is powered by a unique integrated technology for virus detection, based on principles of multi-generation heuristic analysis. This allows the program to protect you from suspect “viral behavior”. This highly effective methodology repelled all attacks of each “I LOVEYOU’ viral variation without any additional antivirus database updates. No other technology, including Norton, Trend, or McAfee was able to accomplish this.

CyberScrub AntiVirus is powerful, yet its exceptional ease of use and installation make it acceptable for beginner to pro



CyberScrub Antivirus constantly scans your hard drive and files to identify, clean and destroy infected objects. With updates available every three hours, 24 hours a day, 365 days a year, you can count on CyberScrub to protect your valued data.

CyberScrub AntiVirus
Lifetime Edition

"For the Life of Your Computer"

Save $10 Now!
Limited Time

 


I-Worm.Skybag.a


Symantec Warns Of Flaw In Antivirus Program. More>>

CNN Legend Lynne Russell reports on CyberScrub AntiVirus for Tech Headline News.


















 
 

delete,deletion, file deletion, Internet clean up,privacy, HIPAA, Internet privacy, cookies, erase, erasure, shredder, wipe, overwrite, purge, deletion, security, file wipe, data destruction