Computer Associates SOLUTIONS   SUPPORT   NEWS & EVENTS   ABOUT CA   INVESTORS   WORLDWIDE  SEARCH
Virus Information Center
 
  Virus Information Center   

Win32.Fili.A

Description Published: October 18, 2004
Description Modified: October 19, 2004

Threat Assessment Low
verylow
medium
medium
Characteristics

Category: Win32

Also known as: W32.Fili.A@mm (Symantec), Win32/P2P.Unknown.Worm, I-Worm.VB.q (Kaspersky)

Immediate Protection Info
eTrust Antivirus 6x/v7* (InoculateIT Engine)23.66.90View Removal Instructions
eTrust Antivirus 6x/v7* (Vet Engine)11.x/8661View Removal Instructions
eTrust EZ Antivirus 6.1x6.1x/5811View Removal Instructions
eTrust EZ Antivirus 6.2x6.2x/8661View Removal Instructions
Vet Anti-Virus 10.5x10.5x/5811View Removal Instructions
Vet Anti-Virus 10.6x10.6x/8661View Removal Instructions

* Includes updates for InoculateIT and eTrust InoculateIT 6.0.
Download Signature Files
Scan For Viruses
Cleaning Utilities
Submit a Virus Sample

Description
Win32.Fili.A is a worm that was designed to spread via P2P networks, IRC, and e-mail. The worm has been distributed as a 20,480 byte, UPX-packed, Win32 executable.
Method of Infection

When executed, the worm displays the Windows shut down prompt screen. This screen appears and disappears continuously for approximately 10 seconds while Windows is active.

It copies itself to %System%\PILIF.EXE  and sets the following registry value to run this file each time Windows starts:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Pilif = “%System%\PILIF.EXE”

Note: '%System%' is a variable location. The worm determines the location of the current System folder by querying the operating system. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; and for XP is C:\Windows\System32.  

Return to top

Method of Distribution

Via P2P File Sharing

In an attempt to spread via P2P file sharing networks, the worm initially locates the following shared folders of the most common P2P programs:

\KMD\Shared Folder
\Kazaa\My Shared Folder
\Morpheus\Shared Folder
\Grokster\My Grokster
\Bear Share\Shared
\Edonkey2000\Incoming
\limewire\Shared
\Shareaza\downloads
\icq\shared files
\WinMX\my shared folder

The worm searches for these folders in the “Program Files” directory, which it locates by referencing this registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\ProgramFilesDir

The worm copies itself to these shared folders using the following file names (note: if these paths do not exist, the worm fails to copy itself):

Norton 2004 Crack
Kasperky AV Universal Key
Dark Coderz Alliance
Anti-hacker Utility
Cracks mega warez collection
Sex – totally free porn
Easy credit card validation
Yahoo hacker
Webmail official hacker
Free porn sites accounts

with these extensions

.exe
.scr
.pif
.bat
.com
.cmd

For example:

C:\Program Files\Kazaa\My Shared Folder\Cracks mega warez collection.pif
C:\Program Files\\Bear Share\Shared\Dark Coderz Alliance.cmd

Via IRC: Intended

In an attempt to spread via IRC networks, specifically targeting mIRC clients, the worm copies itself to the folder “c:\mirc” or “c:\mirc32” as “Manifesto AntiCensore Pilif.txt.exe”. The worm also modifies the file “script.ini” with the intention that the file “Manifesto AntiCensore Pilif.txt.exe” will be sent to anyone that joins a channel that the local affected user is already on.

Due to an error in the modified “script.ini” file, “Manifesto AntiCensore Pilif.txt.exe” is not sent to other mIRC clients. The following message, however, is still sent:

“DCA are fighting for free speech. Get their manifesto now!”

Via E-mail

Win32.Fili.A spreads via e-mail. The worm generates e-mail with variable Message Bodies and Attachment names, although the Subject line is blank. The worm locates e-mail addresses to send itself to using the user's address book. The worm creates the file %System%\adrbook to store collected e-mail addresses.

Possible Message Bodies:

Important legal notice
Do not delete this message. Analyse attachement and reply as soon as possible with manifesto details. Thank you.

Please help us to save the right of freedom of expression.
All details will be displayed in small attached file. Good luck and thank you.

You personal manifesto details are attached. Take good care of them.

Help us gather online votes for our anti-censore manifesto. We need you help now! Attachement will automatically send a vote to our online database once you run it and will be redirected to our webpage!
Thank you.

It’s curious, it’s scandalous… don’t be furious! Life is bitch so don’t take it serious.

Please help us be free! We need the basic right of expression. Enable an online vote for out manifesto with the help of the attachement. Many thanks.

Music is being censored, journalists are afraid, law has not been respected for long time. Why? Because of corruption and lack of right of expression. Help us! Enable the attachement and our voting system will track and record you help. Many thanks.

Parazitii need your help for the anti-censore campaign! See all details in the attachment. Thank you.

Its just hip-hop. Nothing else. Enjoy!
Oh yeah! One more thing: it’s a censore-related manifesto.

This is my manifesto. You can stop this individual, but you cant stop us all… after all, were all alike.

Possible Attachment names.

manifesto 
pilif
sustain cause
details
attachment
request
Parazitii
JOS CeNzura
Freedom
Stolen rights
Details
Manifesto anti pilif
Manifesto details
Freedom of expression
Simple solution
Government issue

The attachment can have any of the following extensions:

.exe
.scr
.pif
.bat
.com
.cmd

Note: In our laboratory testing, the worm sent e-mail without a Subject or Message Body due to a bug in the worm's code. The worm was sent as an attached file with an empty message.

Please see below for an example of e-mail generated by the worm:

Return to top

Payload

Modifies System Settings

The worm disables the Task Manager by setting the following registry value:

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\system\DisableTaskMgr  = 00000001

Closes Windows

The worm closes any windows with titles matching the following list (related to antivirus and other security-related applications):

Agnitium Firewall
Kaspersky Anti-Virus
Kaspersky Anti-Virus Personal
Kaspersky Anti-Virus Scanner
Kaspersky AV Control Centre
Kaspersky AV Monitor
McAfee
Norton Anti-Virus
Norton Firewall
Sygate Personal Firewall
Windows Updater
Zone Alarm

Analysis by Amir Fouda

Return to top

Not at all Extremely
Contact     Legal Notice     Privacy Policy     Site Map
Copyright © 2004 Computer Associates International, Inc. All rights reserved.
Computer Associates