Sophos

W32/Anzae-A

Aliases
  • I-Worm.Pawur.a
  • W32/Anzae.worm
  • WORM_ANZAE.A
  • Tasin
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email attachments
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from June 2005 (3.94)
Protection available since 23 November 2004 09:50:15 (GMT)
Last updated 13 May 2005 10:00:06 (GMT)
Detected by All Sophos products

Action

Please follow the instructions for removing worms.

Windows NT/2000/XP/2003

In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Svchost = %SYSTEM%\svchosl.pif

and delete it if it exists.

Close the registry editor.

More Information

W32/Anzae-A is a Spanish mass-mailing worm. W32/Anzae-A is a Spanish mass-mailing worm.

When run, the worm creates four helper files in the Windows system folder with the names sw.exe, sx.exe, sz.exe and Inzax.exe. W32/Anzae-A will then attempt to create the following registry entry so as to auto-start on computer reboot:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Svchost = %SYSTEM%\svchosl.pif

Possible subject lines:

re:xD no me lo puedo creer!!
re:Crees que puede ser verdad?
re:Amor verdadero
re:Dejate de rollos y vive!!!
re:Psicologia
re:Neptuno y Mercurio
re:La Luna
re:Voodoo un tanto ps...
re:Eso con queso rima con...xD
re:Como el aire...

Possible message bodies include:

No veas que cosas xD,luego me cuentas,chao.
Crees en el amor de verdad?,miralo y ya hablamos,ciaooo
Mira lo que te mando y ya veras que los detalles mas pequenos son los que importan,ciaoo
Ver es creer!!!!chaoo.
Test para ver si andas bien de las neuronassss!xD,luego hablamos,chao.
Que relacion tienen estos planetas?,miralo y luego me cuentas,chao.
Esa moribunda y solitaria Luna,Impresionante!chao.
Sera cierta la magia negra?,sal de dudas y ya me cuentas,chao.
No comment,xDD ,Nos vemos!!
Renvialo a todo que es que se meannn xD,nos vemos!

Possible attachment filenames include:

D-Incognito.zip
Love-Me.zip
EL_rechazo.zip
My life(Mi vida).zip
Psiquico-Mix.zip
Planetario.zip
Moon(Luna).zip
Voodoo!.zip
Rimaz.zip
Para-Brisas.zip

W32/Anzae-A also attempts to delete files from the computer it is running on. The following file extensions are at risk from deletion:

.cpp
.vbp
.vbproj
.frm
.cs
.resx
.vb
.csproj
.sln
.rc
.rc2
.asm
.htm
.html
.php
.asp
.css
.nfm
.dpr
.bdsproj
.pas
.reg
.mp3
.rar
.iso
.nrg
.wav
.doc
.xls
.mdb
.ppt
.rpt
.pdf
.bmp
.jpg
.jpeg
.gif
.pcx
.txt
.c
.h

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer