| ALIAS: | Prolin, Shockwave, W32/Prolin@mm |
| ALIAS: | TROJ_SHOCKWAVE, TROJ_PROLIN |
Prolin is an e-mail worm that spreads itself using MS Outlook. The worm itself is a Windows EXE file about 37Kb long written in VisualBasic. The worm uses the standard "Melissa"-like way of spreading itself: it opens MS Outlook's address book, gets e-mail addresses from there and sends its copies to these addresses.
Subject: A great Shockwave flash movie
Body: Check out this new flash movie that I downloaded just
now ... It's Great
Bye
Attachment: CREATIVE.EXE
The worm then sends a notification message to his author and
informs him about another infected computer:
Then the worm installs itself to system. It installs itself 2
times on an infected computer. One worm's copy is dropped to root
C:\ folder, another one is created in Windows \Start Menu\
folder:
The second copy is specially placed in auto-run directory, so it
will be activated during every Windows session.
The worm has a dangerous payload. It scans all available disk
drives, gets ZIP, MP3, and JPG files and renames them to C: drive
with the name:
For example, BGAMEX.JPG and DATA.ZIP are moved to:
The worm also creates a text file "messageforu.txt" in root C:\
folder writes some text to there and adds a list of renamed files to
the end:
Using this list renamed files can be restored back to their origianal
locations if the infected computer has not been rebooted. Otherwise
the worm removes the list of the moved files from "messageforu.txt"
file.
To: z14xym432@yahoo.com
Subject: Job complete
Message text: Got yet another idiot
C:\creative.exe
C:\WINDOWS\Start Menu\Programs\StartUp\creative.exe
C:\%victimfile%change atleast now to LINUX
C:\BGAMEX.JPGchange atleast now to LINUX
C:\DATA.ZIPchange atleast now to LINUX
Hi, guess you have got the message. I have kept a list of files that I
have infected under this. If you are smart enough just reverse back the
process. i could have done far better damage, i could have even
completely wiped your harddisk. Remember this is a warning & get it sound
and clear... - The Penguin
C:\WINDOWS\SYSTEM\OOBE\IMAGEX\BGAMEX.JPG
C:\BACKUP\DATA.ZIP
[Analysis: Kaspersky Labs, F-Secure Corporation; December 2000]