The Warezov.AT worm variant is very similar to many previous Warezov variants, to
Warezov.W for example.
After the worm's file is run, it shows this messagebox as a decoy:
To ensure its execution every system startup, Warezov.AT creates the following launch points in Windows Registry:
• [HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
"tsrv" = "%WinDir%\t2serv.exe s"
• [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows]
APPInit_DLLs= p2psmsih.dll e1.dll
The worm drops the following files to a system during its installation phase:
• %SysDir%\e1.dll
• %SysDir%\p2psmsih.dll
• %SysDir%\mstle100.dll
• %SysDir%\fsusvcde.exe
• %WinDir%\t2serv.exe
• %WinDir%\t2serv.dll
• %WinDir%\t2serv.wax
• %WinDir%\t2serv.z
• %WinDir%\t2serv.s
The Warezov.AT worm gathers target e-mail addresses from the Windows Address Book (WAB). It may also harvests e-mail addresses from the infected system by scanning through files with the following extension names:
• asp
• cfg
• cgi
• dbx
• eml
• htm
• htm
• html
• jsp
• mbx
• mdx
• mht
• mmf
• msg
• nch
• ods
• oft
• php
• pl
• sht
• shtm
• stm
• tbb
• txt
• uin
• wab
• wsh
• xls
• xml
The worm then sends itself as an attachment to the gathered e-mail addresses using the following e-mail format:
SUBJECT:
The subject may use any of the following strings:
• Error
• Good Day
• hello
• Mail Delivery System
• Mail server report
• Mail Transaction Failed
• picture
• Server Report
• Status
MESSAGE BODY:
It may use any of the following messages:
• Mail transaction failed. Partial message is available.
• The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
• The message contains Unicode characters and has been sent as a binary attachment.
• Mail server report.
Our firewall determined the e-mails containing worm copies are being sent from your computer.
Nowadays it happens from many computers, because this is a new virus type (Network Worms).
Using the new bug in the Windows, these viruses infect the computer unnoticeably.
After the penetrating into the computer the virus harvests all the e-mail addresses
and sends the copies of itself to these e-mail addresses
Please install updates for worm elimination and your computer restoring.
Best regards,
Customers support service
ATTACHMENT:
The attachment is a copy of the worm using the following filename format:
• %filename%.%ext1%.%ext2%
Update-KB%random%-x86.exe
%filename% may use any of the following strings:
• docs
• document
• message
• readme
• text
• test
• data
• body
%ext1% may use any of the following extension names:
• doc
• elm
• log
• txt
• msg
• dat
%ext2% may use any of the following extension names:
• bat
• cmd
• exe
• pif
• cmd
%random%
Example:
• readme.txt.pif
Update-KB1156-x86.exe
The filename is designed to disguise the executable nature of the attachment from the recipient. This worm also uses a text file icon in its attempt to fool recipients into thinking that this file is just a normal text or log file. This is especially true when the - Hide extensions for known file types - option in Windows is enabled. Below is an example.
Readme.txt.pif will be displayed as:

The worm tries to stop services belonging to different firewalls. In addition Warezov.AT worm also attempts to connect to the following websites in order to download 2 files:
• http://www6.vertionkdaseliplim.com/[Removed]/nt.exe
• http://www4.vertionkdaseliplim.com/[Removed]/lt.exe
The download files are two variants of the Warezov worm. One file is an older variant that is detected as
Email-Worm.Win32.Warezov.am, the other file is the latest variant that is detected as
Email-Worm.Win32.Warezov.at. This mechanism is used to automatically update the worm from Internet.
Additionally, the worm contacts the
www3.vertionkdaseliplim.com website to send a notification to the worm's author from an infected computer.