W32/Eira.A@mm

Download VIRUSfighter NOW
W32/Eira.A@mm Destructivity: Spreading: Overall risk:
  
• Detected by virus detection files published: 11/28/2001 • Type: Worm
• Virus characteristics first published: 11/28/2001 • Spreading mechanism: Email, Network
• Virus characteristics latest update: 12/17/2003 • Overall risk: Low
• Alias: I-Worm.Quamo, Win32.Q4Like.A, Win32.HLLM.Rocket.57344 • Payload: Destroys files
• Infection type: Microsoft Windows 95/98/98 SE/ME/NT 4/2000/XP/2003/Vista  

Virus type Spreading
mechanism
Destructivity
and payload
Additional
descriptions
Detection
and removal
Email characteristics:
  • Subject: Variable, see below
  • Body: The worm uses several possible body texts:

    1. Is internet that safe? Check it out

    2. Hey you, take a look at the attached file. You won't believe your eyes when you open it!

    3. You like games like Quake? You will enjoy this one

    4. Did you see the pictures of me and my battery operated boyfriend?

    5. My best friend,
    This is something you have to see
    Till next time
  • Attachment: HONEY.EXE, SETUP.EXE or QUAKE4DEMO.EXE
The worm spreads by sending itself to addresses in the Outlook address book. I has a list of possible subjects and body texts, which it selects randomly from.

Possible subjects are:

1. A brand new game! I hope you enjoy it
2. Something very special
3. I know you will like this
4. Yes, something I can share with you
5. Wait till you see this!

When executed it will copy itself to
C:\EIRAM\QUAKE4DEMO.EXE, F:\QUAKE4DEMO.EXE, %WINDIR%\QUAKE4DEMO.EXE, %WINDIR%\HONEY.EXE and %WINDIR%\SETUP.EXE.

It creates the following registry keys
HKLM\Software\Microsoft\Windows\Currentversion\Run
Q4 = C:\EIRAM\QUAKE4DEMO.EXE
quake = F:\QUAKE4DEMO.EXE

HKCU\Software\Microsoft\Windows\Currentversion\Run
quake = C:\EIRAM\QUAKE4DEMO.EXE
Q4 = F:\QUAKE4DEMO.EXE

It will then display a message screen containing two buttons. The "next" button is disabled, so the only option is to press the "cancel" button, in which case the worm will start its emailing routine.

# - A - B - C - D - E - F - G - H - I - J - K - L - M - N - O - P - Q - R - S - T - U - V - W - X - Y - Z
To protect and serve, VirusFighter