Spy Sweeper with AntiVirus

The most award-winning anti-spyware software

Spy Sweeper with Antivirus

Get serious about removing spyware with Spy Sweeper - the award-winning anti-spyware software trusted by millions of home computer users.

Add to Cart Button

$29.95

Spyware & Virus Directory

A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 


VBS.Kelly.A@mm

Risk Level 2: Low

Discovered: March 21, 2001
Updated: November 19, 2003 11:48:39 AM ZE9
Also Known As: Bloodhound.VBS.Worm
Type: Worm
Infection Length: 6,865 bytes

SUMMARY


This worm sends itself to email addresses in the Microsoft Outlook address book and also spreads to Internet chatrooms using mIRC. This worm overwrites files on local and remote drives, including files with the extensions .js, .jse, .css, .wsh, .hta, and .pwl.

The contents of most of these files are replaced with the source code of the worm, destroying the original contents. The worm also appends the .vbs extension to files with the extensions, .gif, .jpg, and .bmp. For example, image.jpg becomes image.jpg.vbs. It then copies itself to that file name.

Protection

  • Virus Definitions (Intelligent Updater) March 21, 2001

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Moderate
  • Removal: Moderate

Damage

  • Damage Level: Medium
  • Payload Trigger: On execution of email attachment.
  • Large Scale E-mailing: Sends itself to all addresses in the Microsoft Outlook Address Book .
  • Modifies Files: Overwrites files with the following extensions: .js, .jse, .css, .wsh, .pwl, .hta, .jpg, .gif, and .bmp. The overwritten files can be recovered if the user is running NProtect from Norton Systemworks or Norton Utilities at the time of infection.
  • Causes System Instability: Might clog the email server.

Distribution

  • Distribution Level: High
  • Subject of Email: "fw: DO YOU MISS ME ?" or "fw: I MISS YOU VERY MUCH." or "fw: DO YOU COME BACK ?" or "fw: I MISS YOU SO I WAIT YOU."
  • Name of Attachment: "miss.vbs" or "rainbow.vbs" or "kelly.vbs" or "530.vbs"
  • Size of Attachment: 6,865 bytes
  • Shared Drives: Overwrites files located on network drives

TECHNICAL DETAILS


When executed, the worm copies itself to the WindowsSystem folder as these files:
  • C:WindowsAD3.vbs
  • C:WindowsSystemMiss.vbs
  • C:WindowsSystemKelly.vbs
  • C:WindowsSystemRainbow.vbs
  • C:Program FilesNorton AntiVirusNMain.exe
  • C:Program FilesNorton AntiVirusNAVW32.EXE
  • C:Program FilesNorton AntiVirusNsched32.exe
  • C:Program FilesSymantecLiveUpdateLUAll.exe
  • C:Program FilesAntiViral Toolkit ProAvpm.exe
  • C:Program FilesTrend PC-cillin 98PCCWIN98.exe
  • C:Program FilesTrend PC-cillin 2000Pccmain.exe
  • C:Program FilesTrend PC-cillin 98 PLUS!Pccwin98.exe

NOTE: Some of these files use the same file name as legitimate program files. They may be in different locations from the original program files, or they may be copied to the same locations and overwrite the original program files.

For each drive, including network drives, the virus attempts to infect files that have .js, .jse, .wsh, .css, .pwl, and .hta extensions. The worm also searches for files with the extensions .jpg, .gif, and .bmp. When files with these extensions are found, the worm makes copies of the files and adds the .vbe extension to the file name. For example, if a file is named House_pics.jpg, the overwritten file is named House_pics.jpg.vbe. The original file is then deleted. These files must be deleted and then restored from a backup.

CAUTION: Do not attempt to run files that have been overwritten or renamed by this worm. If you do, the worm will be executed again.

The worm uses MAPI calls to Microsoft Outlook, and creates messages by going through all of the addresses in the Microsoft Outlook address book. The worm uses the Windows registry to keep track of those who have been sent the message, so that each is sent only one email message.

The subject of the message is one of the following:

fw: DO YOU MISS ME ?
fw: I MISS YOU VERY MUCH.
fw: DO YOU COME BACK ?
fw: I MISS YOU SO I WAIT YOU.

The body of the message is:

Kelly...Where are you ? I will wait you 3 years.i miss you...Rainbow

The attachment is one of the following:
  • miss.vbs
  • rainbow.vbs
  • kelly.vbs
  • 530.vbs

Summary of modified registry entries
The following registry keys may be added:

HKEY_CURRENT_USERSoftware
MicrosoftOffice9.0WordSecurity


HKEY_CURRENT_USERSoftwareMicrosoft
WindowsCurrentVersionRunAD3


HKEY_CURRENT_USERSoftwareMicrosoft
WindowsCurrentVersionRunmiss

HKEY_CURRENT_USERSoftwareMicrosoft
WindowsCurrentVersionRunKelly


HKEY_CURRENT_USERSoftwareMicrosoft
WindowsCurrentVersionRunainbow


HKEY_LOCAL_MACHINESoftwareMicrosoft
WindowsCurrentVersionRunAD3


HKEY_LOCAL_MACHINESoftwareMicrosoft
WindowsCurrentVersionRunServicesPCCIOMON.EXE


HKEY_LOCAL_MACHINESoftwareMicrosoft
WindowsCurrentVersionNetworkInstalled


HKEY_LOCAL_MACHINESoftwareMicrosoft
WindowsCurrentVersionNetworkLanMan530Path


HKEY_CURRENT_USERSoftwareMicrosoftWindows
CurrentVersionInternet SettingsProxyServer


HKEY_CURRENT_USERSoftwareMicrosoft
Internet ExplorerMainStart Page



Recommendations

Symantec Security Response encourages all users and administrators to adhere to the following basic security "best practices":

  • Turn off and remove unneeded services. By default, many operating systems install auxiliary services that are not critical, such as an FTP server, telnet, and a Web server. These services are avenues of attack. If they are removed, blended threats have less avenues of attack and you have fewer services to maintain through patch updates.
  • If a blended threat exploits one or more network services, disable, or block access to, those services until a patch is applied.
  • Always keep your patch levels up-to-date, especially on computers that host public services and are accessible through the firewall, such as HTTP, FTP, mail, and DNS services (for example, all Windows-based computers should have the current Service Pack installed.). Additionally, please apply any security updates that are mentioned in this writeup, in trusted Security Bulletins, or on vendor Web sites.
  • Enforce a password policy. Complex passwords make it difficult to crack password files on compromised computers. This helps to prevent or limit damage when a computer is compromised.
  • Configure your email server to block or remove email that contains file attachments that are commonly used to spread viruses, such as .vbs, .bat, .exe, .pif and .scr files.
  • Isolate infected computers quickly to prevent further compromising your organization. Perform a forensic analysis and restore the computers using trusted media.
  • Train employees not to open attachments unless they are expecting them. Also, do not execute software that is downloaded from the Internet unless it has been scanned for viruses. Simply visiting a compromised Web site can cause infection if certain browser vulnerabilities are not patched.

REMOVAL


Because the worm copies files that have the same file names as legitimate files to the hard disk, if the worm has already executed, Norton AntiVirus may have to be reinstalled. Follow these steps:
  1. Try to start Norton AntiVirus (NAV). What you do next depends on whether or not it starts.
    • If NAV starts:
      1. Run LiveUpdate to make sure that you have the most recent virus definitions. Run a full system scan, making sure that NAV is set to scan all files.
      2. Delete any files detected as VBS.Kelly.A@mm.
      3. Using Windows Explorer, look for the following files and delete any that you find:

        CAUTION: If you use the Find Files or Search utility to locate these, make sure that you only delete the files in the locations shown.
        • C:WindowsAD3.vbs
        • C:WindowsSystemMiss.vbs
        • C:WindowsSystemKelly.vbs
        • C:WindowsSystemRainbow.vbs
        • C:Program FilesNorton AntiVirusNMain.exe
        • C:Program FilesNorton AntiVirusNsched32.exe
        • C:Program FilesAntiViral Toolkit ProAvpm.exe
        • C:Program FilesTrend PC-cillin 98PCCWIN98.exe
        • C:Program FilesTrend PC-cillin 2000Pccmain.exe
        • C:Program FilesTrend PC-cillin 98 PLUS!Pccwin98.exe
      4. Go on to the section titled Edit the registry.
    • If NAV does not start:
      1. Using Windows Explorer, look for the following files and delete any that you find:

        CAUTION: If you use the Find Files or Search utility to locate these, make sure that you only delete the files in the locations shown.
        • C:WindowsAD3.vbs
        • C:WindowsSystemMiss.vbs
        • C:WindowsSystemKelly.vbs
        • C:WindowsSystemRainbow.vbs
        • C:Program FilesNorton AntiVirusNMain.exe
        • C:Program FilesNorton AntiVirusNAVW32.EXE
        • C:Program FilesNorton AntiVirusNsched32.exe
        • C:Program FilesSymantecLiveUpdateLUAll.exe
        • C:Program FilesAntiViral Toolkit ProAvpm.exe
        • C:Program FilesTrend PC-cillin 98PCCWIN98.exe
        • C:Program FilesTrend PC-cillin 2000Pccmain.exe
        • C:Program FilesTrend PC-cillin 98 PLUS!Pccwin98.exe
      2. Follow the instructions in the section Edit the registry. When you have finished editing the registry, return to this section and then go on to step 3.
      3. Reinstall NAV.
      4. Run LiveUpdate to make sure that you have the most recent virus definitions.
      5. Run a full system scan, making sure that NAV is set to scan all files.
      6. Delete any files detected as VBS.Kelly.A@mm.
Edit the registry:

CAUTION: We strongly recommend that you back up the system registry before making any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure you modify only the keys specified. Please see the document How to back up the Windows registry before proceeding.
  1. Click Start, and click Run. The Run dialog box appears.
  2. Type regedit and then click OK. The Registry Editor opens.
  3. Navigate to the following key:

    HKEY_CURRENT_USERSoftwareMicrosoft
    WindowsCurrentVersionRun
  4. In the right pane, delete the following values:

    AD3
    miss
    Kelly
    rainbow

  5. Navigate to the following key:

    HKEY_LOCAL_MACHINESoftwareMicrosoft
    WindowsCurrentVersionRun
  6. In the right pane, delete the following value:

    AD3
  7. Navigate to the following key:

    HKEY_LOCAL_MACHINESoftwareMicrosoft
    WindowsCurrentVersionRunServices

  8. In the right pane, delete the following value:

    PCCIOMON.EXE
  9. Delete the following keys:

    HKEY_CURRENT_USERSoftwareMicrosoftWindows
    CurrentVersionInternet SettingsProxyServer

    HKEY_CURRENT_USERSoftware
    MicrosoftOffice9.0WordSecurity

    HKEY_LOCAL_MACHINESoftwareMicrosoft
    WindowsCurrentVersionNetworkInstalled

    HKEY_LOCAL_MACHINESoftwareMicrosoft
    WindowsCurrentVersionNetworkLanMan530Path

  10. Click Registry, and click Exit to save your changes and close Registry Editor.



Spy Sweeper 5.2 stops spyware in its tracks while offering home computer users the ability to configure the program to suit their specific needs, such as:

Choose a Quick, Full or Custom Sweep: With Spy Sweeper 5.2, you can easily choose to perform a quick, full or customized sweep. If you're looking for an immediate diagnosis, choose a quick sweep. For a pinpointed search, customize your sweep to have Spy Sweeper skip files by folder or file extension. For a deep cleaning, opt for a full sweep.

Exclude Files from a Sweep: Spy Sweeper allows you to save time during a sweep by skipping specific files or different sections of your PC. You can select specific file extension, such as .xls or .mpg to exclude.

Additional Highlights

As soon as it's installed, Spy Sweeper gives 360 degrees of protection against spyware, including:

Simple Sweeps: Detecting spyware and removing unwanted programs found on your computer in three effortless steps

Easy Management: Quickly and simply configure program, sweep and upgrade options

Fast Home: Use the home screen to access the most commonly used functions of Spy Sweeper

Shields Summary: A redesigned shields summary page makes it simple to see at a glance which shields are on or off

Action Alerts: Receive clear, easy-to-understand notifications when new spyware threats are detected

"Spy Sweeper remains a favorite for protection from spyware."



"This program's dominance is apparent as soon as you install it."