Acanze.A

Threat description

Details

Category: Malware
Type: Worm
Platform: W32

Summary

Acanze.A is simple email worm of Italian origin written in Visual Basic. Due to the coding techniques used, the worm will only work properly under Italian Windows versions.



Removal

Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.



Technical Details

Upon execution, Acanze.A will create a hidden, system file named 'login.bat' into %WINDOWS% directory. It will then set a registry key:

" HKLM\Software\Microsoft\Windows\CurrentVersion\Run\msnmsgr = "C:\WINNT\login.bat"

The key allows Windows to start the bat file each time a user logs on.

Under Italian versions of Windows, additional files will be dropped, and the attributes to both file set to hidden, system.

" %WINDOWS%\SYSTEM\HOTPLUG.dll

" C:\Programmi\Windows NT\netapi.dll

The worm will then check whether a connection to an Italian site can be established. If so, it will create e-mail messages containing copy of its body and send them to recipients in Outlook's Contact list.



Detection

Detection for this malware was published on March 8th, 2005 in the following F-Secure Anti-Virus updates: Detection Type:PC
Database:2005-03-08_03




SUBMIT A SAMPLE

Suspect a file or URL was wrongly detected? Submit a sample to our Labs for analysis

Submit Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

Learn More