
ZAFI.B
WORM SPREADING IN THE WILD
Virus Name : W32.Zafi.B@mm
Alias : I-Worm.Zafi.B,
W32/Zafi-B, PE_ZAFI.B.G, Zafi.B, W32.Erkez.B@mm
Virus type : Internet
worm
Threat
level : Medium
Virus
details :
Zafi.B is
a mass mailing worm uses e-mail addresses
collected from the system to distribute infected
mails. The worm also uses P2P network to spread.
The infected attachment size will be 12800 bytes
and it is compressed with FSG.
Zafi arrives
as an e-mail attachment with random message
subject and message body. The infected mail message
body is chosen from English, Italian, Spanish,
Russian, etc. The worm checks the domain name and
selects the language of the infected mail. If the
domain name ends with .it, Zafi.B will send the
infected mail in Italian.
The
infected mail sample is given below.

When the infected e-mail
attachment is executed, it copies itself to
Windows system folder with random exe file name.
It also drops a dll with random file extension.
Then it modifies the registry to load
automatically on next startup. The registry key
modification is given below.
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
_Hazafibb = "%System%\<random file
name>"
HKEY_LOCAL_MACHINE\Software\Microsoft\_Hazafibb
Zafi.B searches C to Z
drives and copies itself to folders containing
the string "share" or
"upload". This string search allows the
worm to spread using file sharing networks like
KaZaA and imesh. The dropped file names will be
winamp 7.0 full_install.exe and Total Commander
7.0 full_install.exe.
Zafi.B worm overwrites
executable files including antivirus programs in
the infected system. Also it will not allow
regedit, msconfig and task manager process. This
worm performs DoS attack on hungary based
security sites. Zafi.B worm appeared on 11th June
2004.
How can I protect my
system?
Solo has incorporated W32.Zafi.B@mm in its signature file to
protect users from this worm attack. Solo
antivirus registered users are already protected
from this worm. Make sure that you have installed
registered version of Solo Antivirus to protect
your system from all virus threats.
How
to remove this worm?
If
you are already infected with this worm, you can
remove it from your computer using Solo Antivirus
software. Solo antivirus can detect and
remove W32.Zafi.B@mm aka W32.Erkez.B@mm worm
safely. Use the following link to Download
30 day trial version of Solo antivirus
to
remove viruses from your computer.

Solo anti-virus not only
scans for all viruses, it contains a unique System
Integrity Checker to protect you from
New Internet Worms, Backdoors and
malicious VB, Java Scripts. It also
effectively removes all existing Internet Worms,
File viruses, malicious VBS, Java scripts,
Trojans, Backdoors, boot sector, partition table
and macro viruses.
You can
purchase Solo antivirus using the link 

|