Antivirus Software

  1. Home
  2. Computing & Technology
  3. Antivirus Software

A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | Encyclopedia Home
Also see: Hoax Encyclopedia | Repair Center | News Briefs | Glossary | Infected Attachments | Prevention Center

Related Links

About.com Report
Threat List
Trend's Description

Music
Aliases: I-Worm.Music, Troj_Music, W32/Music@mm, W95/Music

Type: VBScript Worm
Systems Affected: Windows 32-bit systems
Payload: Worm is self-updating, so functionality could vary
ITW: Yes
Origin:
Description: Music is a VBScript worm received as an email attachment, named MUSIC.EXE. The subject line of the message reads:

Testing to send file

and the body of the email reads:

Hi, just testing email using Merry Christmas music file, not bad music.

If executed, the worm copies itself to C:\Windows\System as SYSMCM.EXE. It also modifies the registry to run on startup. While doing so, the worm displays Christmas pictures accompanied by a musical tune. It then connects to two Inet sites, downloads and saves two additional components named SYSDRV.EXE and SYSTMP.DLL. These files are saved to the C:\Windows directory. A second downloaded component of the worm is copied to Windows\System and, in turn, it sends a copy of the original worm to all recipients in the infected user's Address Book. The worm is self-updating, that is it is able to upgrade its components via the Internet. Thus, functionality of the worm may change over time.
What to look for: Search for the filenames listed in the above description. Also search the HKey_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Run registry key for the following value: SysDrv = path\sysmcm.exe (where path is the Windows\System directory). Also in HKey_Local_Machine\Software\Microsoft look for the value MCM containing:
FirstRun
LastRun
RunMCM
Status
SMTP
Version = 001111
How to prevent it: Do not open attachments received unexpectedly, even from known sources. Keep your antivirus software up-to-date, save and scan any attachments before opening.

About.com Special Features

Build Your Own Website

Step-by-step advice on how to do everything from choosing a Web host to promoting your content. More >

Connect Your Home Computers

Easy ways to connect two computers for networking purposes. More >

Antivirus Software

  1. Home
  2. Computing & Technology
  3. Antivirus Software