|
Payload: Will delete 5 files from the computer.
Will also attempt to format the C Drive the next time the computer
restarts (Windows 95/98/Me).
Large scale e-mailing: Mails itself to all addresses in
the Outlook Address book
Deletes files: Deletes 5 files with the extension .xls,
.doc, .wav, .dwg, .mp3, .bak, .cdx, .bmp, .htm, .hlp, .chm,
.jpg, .cdr, .mdb, .dbf, or .ico,
Modifies files: Modifies Autoexec.bat to format the C Drive
Causes system instability: Deletes files used by the Windows
Me Operating System to restore corrupted files.
W32.Hunch.C@mm is a mass-mailing worm. If it is run, it does the following:
1. It sends itself to all contacts in the Microsoft Outlook address book. The message has the following characteristics:
Subject: <This varies depending on the originating file name>
Message: Tal como te prometi; te envio mi foto en el archivo adjuncto...
Attachment: <This varies depending on the originating file name>
2. It displays a pornographic picture.
3. It searches the C:\_RESTORE folder (Windows Me only) and deletes all .ocx, .sys, and .dll files from that folder.
4. It copies itself as:- C:\Windows\System\Msoffice.Exe
- C:\Windows\System\Thd16.Exe
- C:\Windows\System\<Attachment file name>
5. It adds the value
THD16 C:\Windows\System\Thd16.Exe
to the registry key
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm runs when you start Windows.
6. It then deletes five files that have one of the following randomly chosen file extensions:- .xls
- .doc
- .wav
- .dwg
- .mp3
- .bak
- .cdx
- .bmp
- .htm
- .hlp
- .chm
- .jpg
- .cdr
- .mdb
- .dbf
- .ico
NOTE: It keeps a log of the deleted files in C:\Windows\System\ListWin.txt.
7. Finally, it modifies the C:\Autoexec.bat file by adding the following command:
DEL > FORMAT C: /u /v:THD16 /autotest
so that the next time that you start the computer (Windows 95/98/Me only) the hard drive is reformatted.
|