United Kingdom
  • UK Support
  • My Account
  • Renewal Centre

Bitdefender®

  • Home
  • Home Users
  • Small Business
  • Corporate Business
  • ISPs
  • News
  • About Us
  • Partners
  • Home
  • Defense Center
  • Virus Information for - Win32.Worm.Antinny.BJ
BitDefender Products
  • Home Products
  • BitDefender for your Business
About BitDefender
  • About Us
  • Company Overview

Win32.Worm.Antinny.BJ

( Worm.Win32.Antinny.aw, Win32/Antinny.AK!Worm, WORM_ANTINNY.BJ, W32/Antinny.worm.ab, W32/Antinny.BP )
Spreading: low
Damage: medium
Size: 278 KBytes (packed)
Discovered: 2006 Apr 14

SYMPTOMS:

Existence of %WINDOWS%\UP\ folder
Existence of a zip file in %WINDOWS%\UP\ folder
Existence of C:\ÄEÉl.scr
Win.ini modified (see technical description for more)
 

TECHNICAL DESCRIPTION:

This virus arrives via Winny peer-to-peer application or file-sharing networks that use Share.exe
If the user is tricked into executing the scr file, the virus will do:

1. Display a fake message in Japanese.

2. Creates and runs a copy of itself as:

C:\ÄEÉl.scr (C:\(japanese text).scr)

3. Creates and deletes file FILE.BAT that attempts to delete itself and the virus copy created previously. However, deletion of C:\ÄEÉl.scr will not work, while FILE.BAT will be deleted.

4. Modifies WIN.INI file with an infection marker

[ÄEÉl]
ÄEê╙=1

5. Creates a folder UP in %WINDOWS% folder:

%WINDOWS%\UP\

This folder will be shared in Winny and Share application. A zip file containing a copy of the worm and some documents will be created here.

6. Searches for Winny and Share application folders.

7. If Winny application is installed, the virus modifies the configuration file UpFolder.txt for Winny file-sharing application:

[BBS]
Path=%WINDOWS%\Up\
Trip=(date_of_infection)-(time_of_infection)

8. If Share application is installed, the virus modifies the configuration file Folder.ini for the Share application:

[UpFolder1]
Path=%WINDOWS%\Up\

9. Searches for files matching:

.doc
.xls
.mdb
.ppt
.dbx
.eml

10. Spreading and information theft:
Creates a zip file in shared %WINDOWS%\UP\ folder:

%WINDOWS%\UP\[ÄEÉl] user_name(date_of_infection-time_of_infection)(random japanese characters).zip

that contains a copy of the worm (random japanese characters).scr

and also files found at step 9 (information theft)
 

Removal instructions:

Please let BitDefender disinfect your files.
 

ANALYZED BY:

Patrik Vicol ,virus researcher

© 2010 BitDefender

  • Site Map
  • Legal Terms
  • Site Feedback
  • Global Sites
  • Privacy Policy

For Home Users

  • BitDefender® Total Security 2011
  • BitDefender® Internet Security 2011
  • BitDefender® Antivirus Pro 2011
  • BitDefender 2011 Product Comparison

For Small Business

  • For Small Business
  • BitDefender® Small Business Security for Desktops and File Servers
  • BitDefender® Small Business Security for Desktops, File Servers, and Exchange

News

  • BitDefender Finds IT Security Employees Likely to Disclose Sensitive Information on Social Networks
  • BitDefender Internet Security 2010 Receives Esteemed AV-Test Certification
  • BitDefender launches Total Security 2011 today to offer consumers a simplified and enhanced way to safeguard their online world

Tools & Resources

  • Free Online Virus Scanner
  • Renew Product Licence
  • Download Trial Versions
  • Download Datasheets