ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Bogus IQ test with destructive payload in the wild

By | January 25, 2010, 1:53pm PST

Summary: Researchers from ESET and BitDefender have intercepted two destructive malware variants (Win32/Zimuse.A, Win32/Zimuse.B/zipsetup.exe), posing as an IQ test, and currently spreading in the wild.

Researchers from ESET and BitDefender have intercepted two destructive malware variants (Win32/Zimuse.A, Win32/Zimuse.B/zipsetup.exe), posing as an IQ test, and currently spreading in the wild.

Upon execution, the malware will attempt to spread through removable media using a time-based logic bomb, and overwrite the MBR (Master Boot Record) of all available drives after 40 days for variant A, and 20 days for variant B, making the host’s data inaccessible.

More info on the malware:

The worm uses two ways to spread – either via embedding in legitimate websites, in the form of a self-unpacking ZIP file or as an IQ test program, or via Exchangeable media, such as USB devices. The fact that it relies on USB devices to propagate is responsible for its rapid dissemination, which is likely to increase even further.

To date, the worm’s two variants - Win32/Zimuse.A and Win32/Zimuse.B differ in the method of spread and the timing of activation. While the A-variant needs 10 days to start spreading via USB devices, its B-variant needs only 7 days since infiltration. Moreover, the time needed for the execution of the destructive routine is shortened in the B-variant from the original 40 days to 20.

Moreover, once executed, the malware will also issue the following, typical for scareware/fake security software error message, in what appears to be an attempt by the malware authors to make the infected users contact the hosting provider of a particular site stating that it infected them with malware:

“System Defender - Kernel Error 0xC00000005

This problem is unambigously cause by malicious contents in IP packers in transport layer from website: www.offroad-lm.szm.sk. To bee patient, Windows Defender scan your hard drive(s) for bugs caused by system incompatible code. To recovery of system press OK button. Wait to successfull end of scanning. Inform about this administrator on www.szm.sk and incriminated web site.”

BitDefender points out that due to the digitally signed drivers in 64-bit versions of Windows Vista and Windows 7, the worm would fail to install. A video demonstrating the infection has been released, as well as a Zimuse removal tool, available for free download.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response.

Disclosure

Dancho Danchev

More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile.

Biography

Dancho Danchev

Dancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog sharing real-time threats intelligence data with the rest of the community on a daily basis. More details on Dancho Danchev's current and past professional affiliations, can be found in his LinkedIn profile. You can also follow him on Twitter
66
Comments

Join the conversation!

Just In

RE: Bogus IQ test with destructive payload in the wild
lovedong 13th Sep
Wow, that's a big compliment! Thank you very much happy rolex watches
0 Votes
+ -
Long story short
Cylon Centurion 25th Jan 2010
Don't download useless crap, and always read the
error messages.

The fact that the one pictured makes no sense and
is full of spelling errors should tell you there
is something fishy going on...
0 Votes
+ -
Better still...
The Mentalist 25th Jan 2010
Don't install useless crap on your machine, especially crappy OSes and always read the security reports.

The fact that the crappy OSes full of programming errors and security flaws should tell you there
is something fishy going on...
0 Votes
+ -
Better Still
scruff40 25th Jan 2010
Please go somewhere else to spout your nons
ense , your hatred of software is borderline
scytzo.
0 Votes
+ -
Habla ingles?
AzuMao Updated - 28th Jan 2010
"ense"
"nons"
"scytzo"

Que???
0 Votes
+ -
Wow two for two today...nt
ItsTheBottomLine 26th Jan 2010
nt
Wow, that's a big compliment! Thank you very much happy rolex watches
0 Votes
+ -
And the windows security fiasco goes on
The Mentalist 25th Jan 2010
After disabling USB drives I wonder what they will do next to prevent windoze from getting infected.

Disable the power button, perhaps?
0 Votes
+ -
you idiot
SystemVoid 25th Jan 2010
Any developer could write a worm or virus like
this, for any operating system. Windows just
happens to be the biggest target. So don't give us
this crap about how it's nothing more than a
"Windoze" problem.
insults come in a close second.

And why such bad humor, why?

Does the sight of your favorite inflatable doll, punctured, affect you that bad?
0 Votes
+ -
lol, ok
SystemVoid 25th Jan 2010
Logic:
All operating systems are vulnerable, because
they're written by humans.

Fact:
C/C++ is not exclusive to Windows. Hence, it
can be used to write worms and viruses for any
OS, given that you know how.

I found no humor in my previous post. I'll
leave the inflatable doll to your imagination.
0 Votes
+ -
But Linux is as safe as swiss road while windows is as safe as a South African road.

There's the difference.
0 Votes
+ -
Bad analogy
Cylon Centurion 25th Jan 2010
Any road can be dangerous given the conditions.
0 Votes
+ -
Agreed
zdnet-gregc 26th Jan 2010
The analogy doesn't really work. Or rather, it can be used to support all kinds of conflicting conclusions. For instance (and I happen to believe this one), the amount of traffic and driver skill are dominant safety factors. A safe driver can negotiate some very bad roads. And road quality can't protect bad drivers from themselves.

Given the vast numbers of Windows drivers on the roads, simple demographics dictate that quite a few of them will be dangerous.

Does anyone seriously believe that if Windows had 85%, that the news would still be about windows exploits?
0 Votes
+ -
give me
SystemVoid 25th Jan 2010
statistics. Analogies are weak. They prove
nothing, and they don't make your argument. I'm
gonna need more than that.
0 Votes
+ -
A lot of nice, paved, dangerous roads
John Zern 25th Jan 2010
right here in the USA!
0 Votes
+ -
There's a difference with technology
Info-Dave 26th Jan 2010
The Windows cars can only crash into other Windows cars, not Mac cars
or Linux cars. Mac cars and Linux cars don't seem to crash. Some say it
is because there are so fews Mac and Linux cars on the road. Some say it
is because of the superior crash prevention technology built into Mac and
Linux cars. I say it is because we are excellent drivers!
0 Votes
+ -
All roads, except roads with zero traffic on them are dangerous. You're just as dead on Swiss roads as you are on a South African road should something unfortunate occur.

There proportionately as many LINUX virus/trojan horse/worms/etc out there as there are for ANY other OS, including Windows.
0 Votes
+ -
No there aren't.
AzuMao 26th Jan 2010
nt
0 Votes
+ -
What makes you think it was written in C or C++..
AzuMao Updated - 26th Jan 2010
..and not a Windows exclusive language?
0 Votes
+ -
because...
SystemVoid 28th Jan 2010
only an idiot would attempt to write a virus in
Visual Basic.
0 Votes
+ -
"Attempt"?
AzuMao 28th Jan 2010
Several have succeeded. It's pretty much the only
use of VB. So easy to "program" in that anyone and
their grandma can do it, yet not so abstracted
that you can't do anything malicious with it.
0 Votes
+ -
devil
0 Votes
+ -
In your case:

- Insults come in first.
- You're the master of bad humor.
- Now we know what caused your mental break-down!
0 Votes
+ -
LOL - nt
ItsTheBottomLine 26th Jan 2010
nt
0 Votes
+ -
Hilarious Haters
bobh2000 Updated - 26th Jan 2010
Henry Ford and Bill Gates must both have had the same head shaking inner laughs.

No matter what the topic is in any ZDNet message thread there always exists the "Windows sucks and will never last" faction. The posts usually fall into the category of "same post, different thread". No originality and no reality based comparison of anything that would support their opinion. And nothing to do with the topic of the original message that was posted.

When it was Henry Ford the "automobile haters" laughed and pointed every time they rode past a broken down model A in their favorite horse and buggy. They laughed and pointed and snickered about how the automobile will never replace the horse!

Today the anti Microsoft folks laugh and snicker every time an error occurs in a few billion lines of code. They point and laugh and say "look Windows will never last" and then they talk about the magic of "mythware" that a couple of hundred people use and "that never has errors".

Being pure scientists, they use the concept that something that has only failed once in 100 tests must somehow be better than something that fails 20 times in 20 million tests because, afterall, the number 20 is 20 times greater than the number 1.

Keep it up people. You are a hoot. I look forward to reading about you when they post the annual Darwins Awards.
Typical know nothing Windows hater. Where is the fiasco? There have been plenty of Windows malware floating around in the past and there will be plenty more in the future and I see no Windows machines grinding to a halt around me. Far from a fiasco, its more like a success when one considers the volume of threats around for Windows.

You might just as well give your self a rest and clam up about things you clearly don't understand and insist on exaggerating about beyond all reason.
0 Votes
+ -
nt
0 Votes
+ -
Firefox is a malware
sadly2010 25th Jan 2010
Don't install Firefox.
0 Votes
+ -
Clueless
rag@... 26th Jan 2010
Yeah, man...I remember when I had my first beer.
0 Votes
+ -
Priceless
martyh@... 26th Jan 2010
My day is only just beginning, and you've already
given me the smile of the day. happy
0 Votes
+ -
Don't install Firefox
sealman546 26th Jan 2010
What's the reason? I've been using it for over a year with never a problen.
0 Votes
+ -
New Jerk On the Block
ejhonda 26th Jan 2010
Or "NJOTB", for short.
0 Votes
+ -
But Windows is THE malware.
AzuMao 26th Jan 2010
Even if you've already installed it, go out of your way to get rid of it.
I saw this on Bitdefender blog http://bit.ly/6JVNps and thought- this worm is pretty smart- and I have 32 bit system...so you re never to safe:D
0 Votes
+ -
Those who have high enough IQ's to ignore the
bait passed, and the idiots of the world who
didn't failed.... Seems like a pretty good IQ
test to me...
0 Votes
+ -
Windows users have low IQ's...
Use_More_OIL_NOW 25th Jan 2010
Study finds 'point & clickers' have low
IQ's...
0 Votes
+ -
Re Wndows users have low IQ's
douglaskey06@... 26th Jan 2010
Unadulterated crap spouted by a Low Ignorant Nerd Using Xtc
0 Votes
+ -
IQ
wjvision1 Updated - 26th Jan 2010
me not dum wink
Maybe people will never learn to just avoid using Windows online.
0 Votes
+ -
It's like a Wet Paint sign ....
kd5auq 26th Jan 2010
.... some people just CAN'T resist!
wink
0 Votes
+ -
Is the stupidity in users or elsewhere?
vbnomad@... 26th Jan 2010
Wouldn't it be great if we could get rid of all those stupid users we hold is such disdain. And that crappy OS that dominates business and consumer computing world-wide. All you little boys and girls could stop working in IS and go back to cutting grass and delivering papers. And the real programmers would be coding Fortran on mainframes - locked safely behind glass walls. Gosh; the good old days...
Maybe in the not to distant future they will replace the "stone age" with the "mainframe age"?
wink
0 Votes
+ -
Sounds like a good IQ test to me!
scott1329 26th Jan 2010
If you're dumb enough to fall for this, you know your IQ is low.
Could you tell me more about the appearance of the email?
0 Votes
+ -
ROFL
LiLac22281 26th Jan 2010
You guys are so funny! I love reading these posts! FYI: it's an IQ test not a CSQ (common sense quotient)test. Sometimes experience is the best teacher. I clicked on an IQ test before too, but when they wanted my whole life history, I said, "Oh, heck no!" Then I did a virus scan. So don't pick on the unsuspecting people who just want to see how "smart" they are. Everyone in the world (or on ZDNet for that matter) isn't an IT wizard or computer geek. Have a nice day!
0 Votes
+ -
Anyone wanting to fill out a IQ test has a superiority or inferiority complex - either you think you're too smart or want to prove you are smart. Getting infected serves you right - you do deserve what you get. I don't give a rats-ass what anyone thinks about me. I expect some nerd to reply that IQ tests prove otherwise - why not go find that malware and find out?
0 Votes
+ -
IQ is pretty limited
DErentzen Updated - 26th Jan 2010
I'll preface this by admitting that I've taken IQ tests and my opinion is not based on sour grapes because of a low score. I've been quite pleased with my results, but that was mostly before I did some research.

IQ measures logical problem solving ability, spatial reasoning, and culture-specific general knowledge. There are many other areas that belong on any true test of overall intelligence.

Interpersonal skills, artistic ability, focus/discipline, an eye for beauty, musical talent, and other factors are predictors of "success" in life that don't rely on anything measured by an IQ test.

High IQ alone won't get you anywhere.

The "smartest" guy I personally know works as a janitor and doesn't strike me as a happy man. His high IQ lets him feel superior to those whose messes he's cleaning up, so I guess it's some kind of consolation, but ...
0 Votes
+ -
superiority or inferiority
drdunc 26th Jan 2010
By the way your telling us about people who do IQ tests, I'm guessing you have a superiority complex... or perhaps you failed. (lol yes, I know you can't actually fail an IQ test)
To quote "I don't give a rats-ass what anyone thinks about me." So that would mean you'll never reply to anyone complimenting or hassling you. Otherwise it'll show you do care and your hypocritical.

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix