Class Email-Worm
Platform Win32

Technical Details

Cervivec is an Internet worm virus spreading via the Internet as an email attachment.

The worm itself is a Windows PE EXE file about 230Kb in size, written in Delphi. It is compressed by UPX – the decompressed size is about 670Kb.

The infected messages have Subject/Body content randomly selected from different variants in different languages:

Cau posilam ti cerviky tak se na to podivej (virus to neni)

Cau posielam ti cerviky tak sa na to pozri (virus to neni)

Hallo, Ich habe ein guter Witz-Wurm so sieh! (kein virus)

J’ai une bonne blague ca s’appelle verre de terre alors jette un coup d’oeil
(il n’y a pas de virus)

?��??�, ‘ ?-� ?��� ?��?R’�- � ����? ?�R?? �?�?�? (��R -? ?����)

Hi, I have some cool joke – worms so have a look at it (no virus)

Czesc, mam swietnz dowcip – robaka. Obejrzyj go sobie (to nie jest wirus)

Hola te mando los gusanilloes. Pues mirarlos (no es un virus)

The worm activates from infected email only if a user clicks on the attached file. The worm then installs itself into the system, runs its spreading and ‘effect’ routines (colored “worms” eating the desktop).

While installing itself the worm copies itself to the Windows directory and to the SYSTEM32 subdirectory with the name “ntkrnl.exe”. It then registers that file in the system registry auto-run key:

Kernel Loader = %WindowsDir%system32ntkrnl.exe -LOADDRIVERS=TRUE

Find out the statistics of the threats spreading in your region