FRISK Software International


Summary of W32/Choke
Alias:Choke, I-Worm.Choke, Win32.Choke, w32/Choke
Discovered: 1 Jun 2001
Infection Method:Via MSN-messenger instant messaging service
 
Jump to:
Brief description
Technical description
Removal Instructions

Brief Description
Choke is a worm that utilises MSN Messenger for spreading. It sends itself using filenames like 'ShootPresidentBUSH.exe', 'choke.exe' and 'George.W.Bush@whitehouse.gov' as username.


Technical Description
When executed it copies itself to 'c:\choke.exe' and creates a key in the registry under

 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run'
with the name 'Choke' and the value 'c:\choke.exe -blahhh' to ensure that it will be started at every system startup. After this it exits with and error message saying

'This program needs Flash 6.5 to run!' 
It creates a file 'c:\about.txt' with this content:

 Choke , Copyright  1886  ... A MAD CHRISTIAN
 ---------------------------------------
 Go talk swearwords about God
 You all will die, stupid humans.
 You fools didn't see what you have done
 Bye slut, go talk shit about me.
 (Call me a 'psychophatt', but I respect the Creator of life...)
 ' Consider your earth '
The worm sends messages to random ICQ users (using 'xxxxxxx@pager.icq.com') saying:

 'Micro$oft invites you to use MSN Messenger!'


Removal Instructions
To remove it it's enough to delete the file 'c:\choke.exe'. If it's locked exit to DOS first then delete it.

[Analysis: Gergely Erdelyi, F-Secure Corp.; June 2001]
 


Stay up to date with important developments via e-mail.
Stay up to date with life cycle policies for F-PROT Antivirus for Windows.
Virus news and information directly to your desktop.
Definitions of common antivirus terminology.
For further virus information, please try our partners' websites:

Authentium

perComp Verlag
(in German)
 

agoat@klaki.net argentina@f-prot.com argentina@frisk.is argentina@complex.is argentina@f-prot.is argentina@frisk-software.com argentina@f-prot.net argentina@f-prot.co.uk brazil@f-prot.com brazil@frisk.is brazil@complex.is brazil@f-prot.is brazil@frisk-software.com brazil@f-prot.net brazil@f-prot.co.uk malta@f-prot.com malta@frisk.is malta@complex.is malta@f-prot.is malta@frisk-software.com malta@f-prot.net malta@f-prot.co.uk a.bjani@f-prot.com a.bjani@frisk.is a.bjani@complex.is a.bjani@f-prot.is a.bjani@f-prot.co.uk a.bjani@frisk-software.com a.bjani@f-prot.net z.fifl@f-prot.com z.fifl@frisk.is z.fifl@complex.is z.fifl@f-prot.is z.fifl@f-prot.co.uk z.fifl@frisk-software.com z.fifl@f-prot.net strumpuri@complex.is strumpure@complex.is strumpuru@complex.is