FRISK Software International


Summary of W32/NakedWife.A@mm
Alias:NakedWife, I-Worm.Naked, W32.HLLW.JibJab@MM TROJ_NakedWife
Length: 73728
Discovered: 1 Mar 2001
Definition files: 1 Mar 2001
 
Jump to:
Brief description
Technical description

Brief Description
NakedWife is an e-mail worm that spreads as an attachment called NakedWife.exe. The worm uses MS Outlook Address Book to find e-mail addresses and sends itself to these addresses with the help of MS Outlook application. The worm is a PE executable about 74 kb long written in Visual Basic. The most probable origin is Brasil.


Technical Description
When the worm is run it shows a dialog box that looks like a ShockWave Flash executable animation's dialog.

All menus in the dialog box are fake except the 'Help' menu. When a user clicks on it, the worm displays a messagebox with the text 'You're are now FUCKED! (C) 2001 by BGK (Bill Gates Killer)'

It should be noted that the worm's file has an icon similar to ShockWave Flash executable animation files and can confuse many users.

After the worm shows its dialog box, it opens MS Outlook Address Book and sends itself to all addresses found there. The infected message has the worm's executable as NakedWife.exe attached. The infected message looks like that:

Subject: 


 Fw: Naked Wife

Body: 


 My wife never look like that! ;-)


 Best Regards,
 

where is the name of an infected computer user.

After the worm sends itself it performs a destructive action. It deletes all *.INI, *.LOG, *.DLL, *.EXE, *.COM and *.BMP files (in that order) in root Windows folder and then deletes all *.INI, *.LOG, *.DLL, *.EXE, *.COM, and *.BMP files in Windows System folder. A system attacked by this worm becomes unusable shortly after that.

If you receive a message with NakedWife.exe attached, don't run the file (don't click on the attachment), delete the message to avoid infection.


[Analysis: Alexey Podrezov; F-Secure; March 2001]
 


Stay up to date with important developments via e-mail.
Stay up to date with life cycle policies for F-PROT Antivirus for Windows.
Virus news and information directly to your desktop.
Definitions of common antivirus terminology.
For further virus information, please try our partners' websites:

Authentium

perComp Verlag
(in German)
 

agoat@klaki.net argentina@f-prot.com argentina@frisk.is argentina@complex.is argentina@f-prot.is argentina@frisk-software.com argentina@f-prot.net argentina@f-prot.co.uk brazil@f-prot.com brazil@frisk.is brazil@complex.is brazil@f-prot.is brazil@frisk-software.com brazil@f-prot.net brazil@f-prot.co.uk malta@f-prot.com malta@frisk.is malta@complex.is malta@f-prot.is malta@frisk-software.com malta@f-prot.net malta@f-prot.co.uk a.bjani@f-prot.com a.bjani@frisk.is a.bjani@complex.is a.bjani@f-prot.is a.bjani@f-prot.co.uk a.bjani@frisk-software.com a.bjani@f-prot.net z.fifl@f-prot.com z.fifl@frisk.is z.fifl@complex.is z.fifl@f-prot.is z.fifl@f-prot.co.uk z.fifl@frisk-software.com z.fifl@f-prot.net strumpuri@complex.is strumpure@complex.is strumpuru@complex.is