Classification

Category :

Malware

Type :

Worm

Aliases :

Funny, I-WORM.Funny, VBS/Funny

Summary

Funny worm spreads in a similar way as LoveLetter. All three known variants of this worm drop, run and delete a binary file Startx.exe that is a password stealing trojan detected by F-Secure Anti-Virus as 'Trojan.PSW.Hooker.24.e'. This trojan is run if the virus found a UBS banking software installed on the victim's machine. Otherwise it replicates as a worm.

Removal

Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.

A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:

  • Check for the latest database updates

    First check if your F-Secure security program is using the latest updates, then try scanning the file again.

  • Submit a sample

    After checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.

    Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.

  • Exclude a file from further scanning

    If you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.

    Note: You need administrative rights to change the settings.

Technical Details

Variant:Funny.A

This variant sends email to all recipients in Outlook address book with:

Subject: Funny story
 Attachment: FUNNY_STORY.HTM.vbs

In addition, it tries to connect to a web location.

Variant:Funny.B

This variant is similar with Funny.A, but it sends messages with the following:

Subject: When did you die?
 Attachment: LIFE_ASSURANCE.HTM.vbs

Variant:Funny.C

Funny.C spreads in messages with:

Subject: Rechnungsabschrift
 Attachment: RECHNUNGSABSCHRIFT.DOC.vbs

This variant does not try to connect to the web. It creates a text file RECHNUNGSABSCHRIFT.DOC and open it with Write.exe. The text file contains the following information:

INVOICE

 Date:
September 18, 2000

 From:
Katrin Heinze
19, chemin des Aulx
CH-1228
Plan-les-Ouates,
Geneva
Switzerland

 To:
 Myron Schmidt"
Ch. des Boveresses 151
CH-1066 Epalingess/Lausanne
Switzerland

 Item

Description

 Item

Description Cost

1August Voice Mail ChargesCHF
35.00

 1Internet - Reserve Domain Name (2 years)
 CHF
250.00

 1Internet - Set Up Fee

CHF
110.00

 1Internet - Creation Fee
CHF
250.00

 1Internet - Submit to 540 Search Engines

CHF
50.00

 1Internet 6 Months of Hosting
 CHF
200.00

 Total
 CHF 895.00