W32/Pretty.worm.unp
 
Profile

To Download DAT update click here .

To Download Fix click here .

Name
W32/Pretty.worm.unp

Aliases
I-Worm.Prettypark.unp, Pretty Park.exe, Southpark Trojan

Variants
None

Date Added
2/17/00

Information
 Discovery Date:2/15/00
 Length:60,928
 Type:Trojan
 SubType:worm
 Risk Assessment:High
 Minimum DAT:4067
 Minimum Engine:4.0.25

Characteristics
This is an Internet worm that installs on Windows 9x/NT systems. It arrives via email from affected users who have also run this Internet worm. It appears as an icon of a character from the animated comedy series "Southpark". Emails containing this Internet worm have this format:

-------------
Subject: C:\CoolProgs\Pretty Park.exe

Test: Pretty Park.exe :)
-------------

Attached is the file "Pretty park.exe" and in some cases "Pretty~1.exe".

This worm will try to email itself automatically every 30 minutes to all email addresses listed in the Windows address book associated with Outlook Express.

A second function of this worm is that it will also try to connect to an IRC server and join a specific IRC channel. While connected, this worm tries to stay connected by sending information to the IRC server, and will also retrieve any commands from the IRC channel. While on the determined IRC server, the author of this worm could use the connection as a remote access trojan in order to get information such as the computer name, registered owner, registered organization, system root path, and Dial Up Networking username and passwords.


Symptoms
Emails containing this Internet worm have this format:

-------------
Subject: C:\CoolProgs\Pretty Park.exe

Test: Pretty Park.exe :)

Pretty Park.exe Icon
-------------

This program, when run will copy itself to FILES32.VXD in WINDOWS\SYSTEM folder. It then modifies the registry key value "command" located in the location:

HKEY_LOCAL_MACHINE\Software\CLASSES\exefile\shell\open

from "%1" %* to FILES32.VXD "%1" %*. This in essence will cause the FILES32.VXD to run during the execution of any exe file.

Click her to see more info about W32/Pretty.worm virus.