Skip to main content

Anset

Classification

Category:

Malware

Aliases:

  • Anset
  • Antes
  • I-Worm.Anset
  • Worm/Anset
  • Ants

Summary

Anset is a worm that appeared in the wild on 24-25th of October 2001 in Austria and Germany. The worm is a UPX-compressed Delphi file. Two variants are currently known. One variant is 186 kb, the other is 179 kb long.

Removal

Technical Details

The worm usually arrives as email attachment named ANTS3SET.EXE file. When a user runs the attachment, the worm copies itself to \Windows\ directory with a random name (for example RTX.EXE or JNJSLLKE.EXE) and modifies RunOnce subkey of the following Registry key:

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion]

The RunOnce subkey contains the name and path to the worm's file. This way the worm activates itself after system reboot.

To spread itself the worm gets email addresses from Outlook Address Book and from *.PHP, *.HTM, *.SHTM, *.CGI and *.PL files that it can find on local hard drives. Before spreading the worm copies itself as ANTS3SET.EXE to root folder of C: drive. Then the worm sends itself to all email addresses it could find on an infected system. The infected message in both German and English looks like that:

From:\r\nAndreas Haak[webmaster@avnetwork.de] \r\nSubject: ANTS Version 3.0 \r\nReply-To: webmaster@avnetwork.de \r\nBody: \tHi,\r\n Anhangend die neue Version 3.0 von ANTS, dem bislang\r\n einzigartigen kostenlosen Trojanerscanner. Zum\r\n installieren einfach die angefugte Datei ausfuhren.\r\n Attached you will find the brand new Version 3.0 of ANTS,\r\n the unique freeware trojan scanner. To install ANTS\r\n simply run the attached setup file. \tAdieu, Andreas \twebmaster@avnetwork.de \thttp://www.ants-online.de

The worm is attached to the infected message as ANTS3SET.EXE file. The worm uses the following anonymous SMTP servers:

200.52.69.2 200.52.69.9 193.92.94.226 12.34.208.35 195.229.189.2 toad.com 196.40.0.82 196.40.0.90

The Version resource of the worm states:

CompanyName: e-brainstorm FileDescription: ANTS - A New Trojan Scanner LegalCopyright: Andreas Haak

Andreas Haak is a real person who makes scanners against trojans. According to Andreas someone used his name and name of his program to create a worm.

F-Secure Anti-Virus detects this worm with the from 24th of October 2001.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.