Skip to main content

Bogus Patch "leaves" Backdoor Open

July 11, 2001

An Internet Worm "Leave" Spreads in the Form of Security Patch to Windows Kaspersky Lab, an international data-security software development company, warns users of the discovery of a new version of the Internet worm I-Worm.Leave that spreads as a message from Microsoft. The message contains...

An Internet Worm "Leave" Spreads in the Form of Security Patch to Windows

Kaspersky Lab, an international data-security software development company, warns users of the discovery of a new version of the Internet worm I-Worm.Leave that spreads as a message from Microsoft. The message contains information about a security patch for Windows and displays a bogus URL. Upon opening, the virus attempts to download a cvr58-ms.exe file that is in fact a Trojan.

The worm works under systems operating Windows 95/98/ME and Windows 2000 only. When the main worm component is run, it copies itself to the Windows directory with the REGSV.EXE name and registers that file in the auto-run registry keys.

"Leave's" malicious peculiarities allow it to automatically update via the Internet, and, unbeknownst to the user, to activate additional EXE-file components, allowing for the remote control of an infected computer. Amongst the other functions of "Leave," in part, is to connect to IRC servers and execute IRC commands, create, move, delete, execute files on an infected machine etc.

The main worm's components contain a text string that is a SubSeven backdoor master password. So, the worm may attack remote machines already infected by SubSeven backdoor, and install itself there. To obtain victim-machine addresses, the worm uses a scanning routine and scans the Internet for IP addresses of remote machines.

Detection and treatment for "Leave" have already been added to the Kaspersky Lab anti-virus database.

For a more in-depth description of "Leave," visit the Kaspersky Lab virus encyclopedia.

Bogus Patch "leaves" Backdoor Open

An Internet Worm "Leave" Spreads in the Form of Security Patch to Windows Kaspersky Lab, an international data-security software development company, warns users of the discovery of a new version of the Internet worm I-Worm.Leave that spreads as a message from Microsoft. The message contains...
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Innovating the industry with a Cyber Immunity approach, Kaspersky safeguards consumers, businesses, critical infrastructure, and governments from cyberthreats, with over a billion devices protected to date.

Kaspersky ensures Cybersecurity True to Business, focusing on providing clear outcomes, protecting revenue, easing workloads and preventing downtime. Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services for organizations of every size, from small businesses to large enterprises, combining proven AI-driven protection technologies with simple management and expert support.

Recognized in independent tests and trusted by millions of individuals worldwide and nearly 200,000 organizations, Kaspersky helps detect threats earlier, respond faster and operate with greater confidence and freedom, protecting what matters most to our clients. Learn more at www.kaspersky.com.

Related Articles Press Releases