W32.Myparty @mm Virus

Discovered on: January 26, 2002
Last Updated on: January 30, 2002 at 07:21:14 AM PST

W32.Myparty@mm is a mass-mailing email worm. It has the following characteristics:
Subject: new photos from my party!
Message:
Hello!

My party... It was absolutely amazing!
I have attached my web page with new photos!
If you can please make color prints of my photos. Thanks!

Attachment: www.myparty.yahoo.com

The worm sends email to all contacts in your Windows address book, and to email addresses that if finds in the Outlook Express Inboxes and folders.

In addition, the worm sends a message to the author so that the author can track the worm.

On NT/2000/XP systems, the worm drops a backdoor Trojan that allows a hacker to control your system. NAV will detect this as Backdoor.Myparty.

Finally, if the file name of the worm is Access.<any extension>, it may launch your Web browser to http:/ /www.disney.com. However, the worm does not contain code which can generate a file with the name Access.<any extension>, so it is highly unlikely that this will trigger.

Also Known As: W32/Myparty@MM, WORM_MYPARTY.A, W32/MyParty-A, Win32.MyParty, I-Worm.Myparty

Type: Trojan Horse, Worm

Infection Length: 29,696 bytes

Virus Definitions: January 28, 2002

Threat Assessment:

 
Medium Low High
Wild:
Medium
Damage:
Low
Distribution:
High

Wild:

Damage:

Distribution:

Technical description:

W32.Myparty@mm arrives as an email with the following characteristics:

Subject: new photos from my party!
Message:
Hello!

My party... It was absolutely amazing!
I have attached my web page with new photos!
If you can please make color prints of my photos. Thanks!

Attachment: www.myparty.yahoo.com

When it is executed, the worm first checks the date. If the computer date is not between January 25 to 29, 2002 or if the keyboard settings are set to Russian, the worm copies itself to:

C:\Recycled-F-<random digits>-<random digits>-<random digits>

and exits.

Otherwise, the worm continues.

The worm next checks its own file name, and performs different actions depending on the file name or extension:


Finally, the worm sends a message to napster@gala.net, allowing the author to track how far the worm has spread.

Removal instructions:


Write-up by: Douglas Knowles and Eric Chien

Symantec AntiVirus Research Center (SARC)
http://www.symantec.com/avcenter