Win32/Zafi.D

Created: 2006-07-19, 19:28:15
Last updated on: 2010-11-26, 09:32:34

Platform: Win32 Type: worm Size: 11745
Date: 2004-12-14

Compressor: FSG
Endangered operating system(s): Windows 95, Windows 98, Windows Me, Windows NT, Windows 2000 all...
Non-endangered operating system(s): Windows 3.xx, DOS, Linux, Unix, Solaris all...

Naming

The different antivirus applications use different names for the individual viruses and worms. Sometimes an antivirus application identifies the same individual malware using different names for different copies or different viruses and worms are identified with the same name. The informative list below contains the names for the malware given by the most popular antivirus applications. The names can vary using the different versions of the same antivirus application.

antivirus naming
Avast Win32:Zafi-J
AVG I-Worm/Zafi.D
BitDefender Win32.Zafi.D@mm
e-Trust Win32/Zafi.D
F-PROT W32/EmailWorm.OQI
F-Secure Email-Worm.Win32.Zafi.d
Ikarus Email-Worm.Win32.Zafi.D
Kaspersky Email-Worm.Win32.Zafi.d
McAfee W32/Zafi.d@MM(Virus)
Microsoft Win32/Zafi.D@mm
NOD32 (ESET) Win32/Zafi.D
Norton Antivirus W32.Erkez.D@mm
Panda W32/Zafi.D.worm
Rising Antivirus Worm.Zafi.d
Sophos W32/Zafi-D
Trend Micro WORM_ZAFI.AC
VirusBuster I-Worm.Zafi.D

organization naming
Wildlist W32/Zafi.D-mm

Installation

Viruses and worms can initiate some spectacular action. The purpose is usually to attract attention and through the interaction of the user (pushing a button or clicking on the mouse) they make it difficult to automatically proceed the malware in the virtual environment. The worm displays the following window during the installation of its code:

image

The main purpose of viruses and worms spreading on the Internet and local networks is to infect another computer. After this infection malware can modify the system and after a reboot process the malware code can be launched. For this purpose malware usually creates files in the operating system's area and modify the registry. According to this modification of the registry the operating system will execute the malware code as well. Besides, it is possible that they create files in other area (directory) of the file system. It is also possible that viruses and worms create AUTORUN.INF files in the root directories of the drives. In this case - according to the default settings of Windows - it automatically executes the malware once the user opens the root directory of the particular drive.

The worm creates the following files:

In the Windows System32 folder (default: C:\Windows\System32): Norton Update.exe

In the Windows System32 folder (default: C:\Windows\System32) véletlenszerűen generált névvel, melyek kiterjesztése: .dll

In the Windows System32 folder (default: C:\Windows\System32) with random names using the .dll extension.

In the root folder of the drive(s): s.cm

In share folders:

  • winamp 5.7 new!.exe
  • ICQ 2005a new!.exe

image image image image image image

Win32/Zafi.D worm creates the following entries in the registry or modifies it (if it exists already):

  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Wxp4"="C:\WINDOWS\System32\Norton Update.exe"
  • [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wxp4] "t3"="C:\WINDOWS\System32\Norton Update.exe"

Win32/Zafi.D worm creates randomly generated entries under the [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wxp4] key.


image image

Memory resident viruses and worms usually install themselves in the memory only once. For this purpose malware can use the operating feature and they can create mutexes. They can check the existence of this mutex before installing their code into the memory.

Win32/Zafi.D worm creates the Wxp4 mutex.

Viruses and worms can stop the processes related to antivirus solutions and/or firewalls. The first purpose of this is that malware codes can live in the system for a long time. On the other hand if the malware includes a backdoor function then it can work easier. Malware can modify the path of the Internet traffic. Thus some web sites (e.g.: antivirus update pages) become unreachable.

Win32/Zafi.D worm stops processes whose names include one of the following strings:

  • firewall
  • virus
  • reged
  • msconfig
  • task

E-mail messages

The main aim of worms spreading in e-mail messages is to infect other computers. For this purpose they create and send e-mail messages to various e-mail addresses. The body of these messages usually include the code of the worm, but it is also possible that only a link is attached into the body and the user downloads the code of the worm. E-mail worms can create e-mail messages with various parameters.

Win32/Zafi.D worm in order to spread creates ANSI format e-mail messages and forwards its own code.

For a better spreading e-mail worms and viruses use the attacked computer not only for forwarding its code but for searching potential e-mail addresses. These e-mail addresses are used as the addressee of the e-mail message and/or as the sender. Thus the sender address is modified by the malware.

Win32/Zafi.D worm searches for e-mail addresses in the files with one of the following extensions:

Win32/Zafi.D worm can create e-mail messages with different characteristics. This is usually used for worms to send e-mails in different languages to different regions (domains). The characteristics of the e-mail messages are the following:

in case of .hu domain (details...)

in case of .nl domain (details...)

in case of .cz domain (details...)

in case of .fr domain (details...)

in case of .it domain (details...)

in case of .ru domain (details...)

in case of .es, .mx domains (details...)

in case of .dk domain (details...)

in case of .se domain (details...)

in case of .no domain (details...)

in case of .fi domain (details...)

in case of .lt domain (details...)

in case of .pl domain (details...)

in case of .de, .at domains (details...)

in other cases (detailes...)


image image image image image image image

The icon of the messages including worm (warning: in some e-mail clients the icon is not correctly visible):
image

Backdoor

Viruses and worms more and more frequently open backdoors on the attacked computer. Thus the attacker can take full control over the machine. In this case the attacker can do whatever s/he wants on the computer: run or stop programs and applications, upload or download files, steal passwords and access codes.

Win32/Zafi.D worm opens a backdoor on TCP port number 8181 .