Skip to main content

Email-Worm:W32/Luder.A

Classification

Category:

Malware

Type:

Email-worm

Aliases:

  • Email-Worm.Win32.Luder.a

Summary

This type of worm is embedded in an email attachment, and spreads using the infected computer's emailing networks.

Removal

Technical Details

Luder is an email worm, a dropper for a trojan downloader and a file infector. The worm sends itself as attachment named 'postcard.exe' (or similar) in email messages with the 'Happy New Year!' subject (or similar). The trojan downloader downloads and runs files from a website.

Installation

After the worm's file is run, it copies itself to Windows System folder with the name ppl.exe.The worm also drops a trojan downloader file with a random name into the Windows System folder and starts it.

Propagation

Before spreading, the worm collects email addresses from an infected computer. It locates and reads the WAB (Windows Address Book) file. The worm sends messages with the following characteristics:

  • Subject:Happy New Year!
  • Attachment:postcard.exe

Later variants of the worm use different Subject fields and Attachment names.The worm avoids sending emails to email addresses that contain any of the following:

  • microsoft
  • .mil
  • .gov

Activity

The worm scans all fixed and remote drives starting from Z: to C: and looks for files with the following extensions:

  • hta
  • txt
  • htm
  • exe
  • scr
  • rar

The worm collects additional email addresses to spread to files with .hta, .txt and .htm extensions.The files with .scr and .exe extensions get infected. For every executable file found, the worm creates a copy with a random name and a .t extension. Then it tries to infect the files, if they are in PE (Portable Executable) format. The worm inserts a small piece of code into the victim files and then redirects the entry point to that address. This small piece of code starts the worm's copy (randomly named file with .t extension) and then passes control to the host file.It should be noted that the worm is quite buggy and can corrupt files upon infection. Files with .rar extension are not affected, but the worm's author probably plans to process them in future versions of his malware. The worm also does not infect files protected by Windows Safe File Check.The worm terminates processes with the following substrings in their names:

  • anti
  • viru
  • troja
  • avp
  • nav
  • rav
  • reged
  • nod32
  • spybot
  • zonea
  • vsmon
  • avg
  • blackice
  • firewall
  • msconfig
  • lockdown
  • f-pro
  • hijack
  • taskmgr
  • mcafee

In addition the worm closes the Registry Editor's window.

Registry Modifications

Creates these keys:

  • [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "agent" = "%WinSysDir%\ppl.exe"
  • [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] "agent" = "%WinSysDir%\ppl.exe"

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.