Next, the worm will
insert two .vbs files on the system:
- \<Windows folder>\ZaCker.vbs
- \<Windows\System folder>\MixDaLaL.vbs
In addition, the worm will attempt to download and execute a file.
This file is detected as Backdoor.Trojan by Norton Antivirus.
Finally, the worm will attempt to delete all files from several
folders. These folders appear to be the default installation folders
for several antivirus products. For Norton AntiVirus, this worm
will only attempt to delete the files if Norton Antivirus is located
in C:\Program Files\Norton AntiVirus.
What the dropped files do
MixDaLaL.vbs
MixDaLaL.vbs is a Visual Basic Script file that is inserted in the
\Windows\System folder. This file is executed by the worm. As the
file is executed, it will look through all folders on all fixed
drives and network drives for files with the extensions .htm or
.html. If such a files are found, they are overwritten with the
message:
AmeRiCa ...Few Days WiLL Show You What We Can Do !!! It's Our
Turn >>> ZaCkEr is So Sorry For You
ZaCker.VBS
This file is inserted in the \Windows\System folder. It is not executed
by the worm. Instead, the value
Norton.Thar \Windows\System\ZaCker.vbs
is added to the registry key
HKEY_LOCAL_MACHINE\Microsoft\
Windows\CurrentVersion\Run
so that the file is executed when you start Windows.
When executed at the next restart, this file will attempt to delete
all files in the \Windows folder. Next, the worm will create or
overwrite the file C:\Autoexec.bat. Inside the file there will be
a command that formats the C drive. The Autoexec.bat file is executed
on Windows 95/98/Me and DOS systems when you start the computer.
Finally, the worm will displays the message

The worm does attempt to shut down Windows after the message has
been displayed. However, because the files required for this event
to occur have been deleted from the \Windows folder, the computer
probably will not shut down.
|