Skip to main content

Neveg.C

Classification

Category:

Malware

Aliases:

  • Neveg.C
  • I-Worm.Neveg.c
  • W32/Neveg.C

Summary

Neveg.C is a mass-mailing worm with Peer-to-Peer spreading capabilities.

Removal

Technical Details

Neveg.C arrives in email as a packed executable.

System Infection

When the worm's file is run, it copies itself as services.exe to Windows System folder and creates a startup key for this file in the Registry:

[HKLM\ Software\Microsoft\Windows\CurrentVersion\Run] of [HKCU\ Software\Microsoft\Windows\CurrentVersion\Run]

The key value name will be chosen from:

BuildLab RegDone ccApps Microsoft Visual SourceSafe TEXTCONV FriendlyTypeName .Prog WMAudio

And it will point "%SystemDir%\ services.exe"

%SystemDir% represents the Windows System folder name, for example C:\Windows\System32 on Windows XP systems.

The icon for the program will look like this:

Email Propagation

Neveg.C scans the hard drive to collect email addresses of possible victims. Files with the following extensions are checked:

.xml .xls .wsh .wab .vbs .uin .txt .tbb .stm .shtm .sht .rtf .pl .php .oft .ods .nch .msg .mmf .mht .mdx .mbx .jsp .html .htm .eml .dhtm .dbx .cgi .cfg .asp .adb

Neveg.C spreads itself in emails with the following attachment filenames:

office.exe notes.exe doom3demo.exe resume.exe files.exe request.exe info.exe details.exe result.exe results.exe install.exe setup.exe test.exe google.exe se_files.exe

Propagation Through Peer-to-Peer Clients

Neveg.C is capable of spreading to shared folders of Peer-to-Peer clients. It will look for folders with names containing strings from the following list:

shared files shar my shared folder mule morpheus lime kazaa icq http htdocs ftp download donkey bear upload

The worm copies itself there with the following names:

XXX hardcore images.exe Windows Sourcecode update.doc.exe Windown Longhorn Beta Leak.exe WinAmp 6 New!.exe WinAmp 5 Pro Keygen Crack Update.exe Serials.txt.exe Porno, sex, oral, anal cool, awesome!!.exe Porno Screensaver.scr Porno pics arhive, xxx.exe Opera 8 New!.exe Microsoft Windows XP, WinXP Crack, working Keygen.exe Microsoft Office XP working Crack, Keygen.exe Microsoft Office 2003 Crack, Working!.exe Matrix 3 Revolution English Subtitles.exe KAV 5.0.exe Kaspersky Antivirus 5.0.exe Ahead Nero 7.exe Adobe Photoshop 9 full.exe ACDSee 9.exe

The worm also tries to launch a DDoS attack against a series of websites, which apparently all belong to one German company.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.