Summary
This variant of the Redesi worm is based on the same code. It differs
from the original one in the subject lines and message body it uses.
The messages look like they were forwarded messages from Microsoft
Tech Support.
Subjects are chosen from this list:
'FW: Microsoft security update.'
'FW: Security Update by Microsoft.'
'FW: IT departments on state of HIGH ALERT.'
'FW: Terrorists release computer virus.'
'FW: Emergency response from Microsoft Corp.'
'FW: Terrorist Emergency. Latest virus can wipe disk in minutes.'
'FW: Microsoft Update. Final Release Candidate.'
'FW: New computer virus.'
When it sent the messages it displays a fake message:
Payload
Redesi.b has a destructive payload. When it infects the machine
it adds a value to the registry called
'HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Rede'
and sets it to 'c:\rede.exe' so the worm will be started at each reboot.
If the date format is set to either dd/mm/yy or mm/dd/yy on
11th of November in 2001 it adds a some code to c:\autoexec.bat that
will print a message:
'Bide ye the Wiccan laws ye must, In perfect love and perfect trust.'
This sentence is quoted from "The Complete Idiots Guide to Witchcraft and Wicca"
After this, the worm formats the hard drive after the next reboot.
Removal instructions
All the worm files from c:\ must be removed (see above) together
with the modified registry values:
'HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Rede'
'HKLM\Software\Microsoft\Windows\CurrentVersion\ErrorHandling\Rede'
F-Secure Anti-Virus with the latest updates can detect the worm.
[Analysis: Gergely Erdelyi and Sami Rautiainen; F-Secure Corp.; 19th October, 2001]