Skip to main content

Carrytone

Classification

Category:

Malware

Type:

Worm

Aliases:

  • Carrytone
  • I-Worm.Taripox.b

Summary

Carrytone is a mass-mailer that uses a new technique to spread. The worm body is 40 kilobytes in size and it was written in C. It works properly on Windows NT based systems only.

Removal

Technical Details

For spreading it implements a simple SMTP proxy that listens on port 25 (standard SMTP port) on the infected machine. When the worm is started it fetches the SMTP server name from the user's email settings then it modifies the HOSTS file so that the SMTP server's address points to the localhost where the worm is listening. This way when the user sends an email his/her email client will connect to the worm instead of the real mail server. After receiving the connection the worm relays all the commands and replies between the client and the real mail server until it gets the reply to SMTP DATA command that marks the beginning of the email data. At this point it inserts a copy of itself into the message.

The attachment name it uses is composed from the recipient's name and a '.doc.pif' extension.

Messages look like this:

When the infected attachment is opened it copies itself to the Windows folder as 'MMOPLIB.EXE' and adds it to the runkeys in the registry:

  • '[HKLM]\Software\Microsoft\Windows\CurrentVersion\Run\mmopl'

The worm stores some internal data under

  • '[HKLM]\Software\Microsoft\Media Optimization Library'

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.