Home→Descriptions→IM-Worm.Win32.Funner
| Detected | Oct 10 2004 14:04 GMT |
| Released | Oct 10 2004 14:04 GMT |
| Published | Jan 26 2005 12:11 GMT |
This worm spreads via the Internet using MSN Messenger to propagate. It is written in Visual Basic. It is approximately 56KB in size, and packed using ASP. The unpacked file is approximately 306KB in size.
Once launched, the worm copies itself to the Windows system directory under the following names:
%System%\IEXPLORE.EXE %System%\explorer.exe %System%\userinit32.exe
It also copies itself to the Windows root directory as “rundll32.exe”:
%WinDir%\rundll32.exe
The worm then creates a log file names “bsfirst2.log” in the Windows system directory:
%System%\bsfirst2.log
It then registers its copies in the system registry, ensuring that a copy of the worm will be launched each time the system is rebooted:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "MMSystem" = "%Windir%\rundll32.exe "%System%\mmsystem.dll"", RunDll32" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit" = "%System%\userinit32.exe"If the victim computer is running Windows 95/98/ME, the worm will alter a section in the “system.ini” file:
[boot] Shell = %System%\explorer.exe
When launched, the worm accesses the MSN Messenger contact list, and sends a copy of itself, called “funny.exe” to all contacts found.
The worm alters the "%System%\drivers\etc\hosts" file by writing the text listed below to it. This means that any attempts by the user to view the sites listed below will result in the browser being redirected to 222.89.98.219:
IM Worms spread via instant messaging systems (such as ICQ, MSN Messenger, AOL Instant Messenger, Yahoo Pager, Skype, etc.)
In order to spread, IM-Worms usually send a link (URL) to a list of message contacts. The link leads to a network resource where a file containing the body of the worm has been placed. This tactic is almost exactly the same as that used by Email-Worms.
IM-Worm.