When the worm's file is started it shows a fake error message
Error54: Media Player not installed correctly
The worm copies itself to TEMP folder of Windows, adds startup key for that file into System Registry and sends itself to all recipients of Outlook Address Book and Windows Address Book with the following message:
Subject:
FW:FW: LILAC project video attach
Body:
Things that the govt. dont want you to know
Attachment:
LILAC_WHAT_A_WONDERFULNAME.avi.exe
The worm has bugs in its code and can fail to send its attachment. In this case recipients will get an empty EXE file.
Also the worm changes Windows owner information to 'xEnOcrAtEs' and sets logon text to 'Owned by: xEnOcrAtEs'. The worm can display a message:
'Your PC is infected with LILAC virus by: xEnOcrAtEs'
|