MyAntiSpyware


New worm disables Security Software

Myantispyware team June 20, 2006    

Sanbeltblog reported about new World Cup Soccer Worm. The worm arrives as an E-mail attachment with one of the following subjects and message bodys:

Subjects:

1. Soccer fans killed five teens
2. Crazy soccer fans
3. Please reply me Tomas
4. My tricks for you
5. Naked World Cup game set
6. My sister whores, shit i dont know

Message Bodies:

1. Soccer fans killed five teens, watch what they make on photos. Please report on this all who know.
2. Crazy soccer fans killed two teens, watch what they make on photos. Please report on this all who know.
3. I wait your photos from New York. I sent my pics where i naked for you. Please reply me. Linda Salivan
4. Nudists are organising their own tribute to the world cup, by staging their own nude soccer game, though it is not clear how the teams will tell each other apart. Good photos 😉
5. Emily Carr was an artist know for her prudery, but now the Portrait Gallery of Canada has aquired a nude self-portrait. View photos.

Upon execution, the worm copies itself to the following location:

%Sysdir%\msctools.exe

Attempts to download additional malware:

http://couple{removed}.com/tumbs/dianaimg.exe

The worm also attempts to disable the following processes:

AVP32.EXE, AVPCC.EXE, AVPM.EXE, AVP.EXE, iamapp.exe, iamserv.exe, FRW.EXE, blackice.exe, blackd.exe, zonealarm.exe, vsmon.exe, VSHWIN32.EXE, VSECOMR.EXE, WEBSCANX.EXE, AVCONSOLE.EXE, VSSTAT.EXE, OUTPOST.EXE, REGEDIT.EXE, NETSTAT.EXE, TASKMGR.EXE, MSCONFIG.EXE, NAVAPW32.EXE, UPDATE.EXE, msctools.exe

Worms

 Previous Post

Another rogue antispyware app for your blacklist – Trust Cleaner

Next Post 

Found Mailbot family that use ADS hidden streams to hide themselves

Author: Myantispyware team

Myantispyware is an information security website created in 2004. Our content is written in collaboration with Cyber Security specialists, IT experts, under the direction of Patrik Holder and Valeri Tchmych, founders of Myantispyware.com.

2 Comments

  1. FARSHAD
    ― March 15, 2009 - 6:51 am  Reply

    HI SALAM

  2. FARSHAD
    ― March 15, 2009 - 6:52 am  Reply

    The worm also attempts to disable the following proc

Leave a Reply Cancel reply

New Guides

Melt Drops Review: Scam or Legit? What You Need to Know
CartRelief.com Reviews, Scam or Legit, Uncovering the Truth!
JellyThin Reviews, Fake “Pink Gelatin” Trick Scam Exposed, Jillian Michaels?
Bariatric Gelatin Trick Recipe Scam Exposed, Dr. Jennifer Ashton and Jillian Michaels?
ReceiveCodes.com Scam Alert – Don’t Fall for This Fake Costco Memorial Day Promo!

Follow Us

Search

Useful Guides

Iphone Calendar virus spam
Iphone Calendar Virus/Spam 2022 (Removal guide)
DNSChanger
How to remove DNSChanger malware virus [Updated Apr. 2018]
remove chrome extension
How to remove Chrome extensions installed by enterprise policy
Files encrypted by ransomware become useless
How To Recover Encrypted Files (Ransomware file recovery)
search.yahoo.com
Remove Search.yahoo.com Redirect Virus ✅ (Quick & Easy) in 2024

Recent Guides

Another rogue antispyware app for your blacklist – Trust Cleaner
Found new vulnerability in Microsoft Excel
Update your systems
CleanCache – Clean Internet Explorer, Mozilla, Firefox, Opera and most Internet Explorer shells
Automatic remove Titan shield

Myantispyware.com

Myantispyware has been a trusted source for computer security and technology advice since 2004. Our mission is to provide reliable tech guidance and expert, practical solutions to help you stay safe online and protect your digital life.

Social Links

Pages

About Us
Contact Us
Privacy Policy

Copyright © 2004 - 2026 MASW - Myantispyware.com.