Read the same in:      Polski  Русский  English  
You are welcome to subscribe to "New articles in Knowledge Base" mailing list.




Virus Activity

Virus Activity

virus activity is normal




 
Search :  
Search tips Article ID # :     
 

How to remove malware Worm.Win32.NeKav.a (eKav)

This section explains how to neutralize complicated malware, i.e. when user participation is required to modify the system registry or execute a special utility, for example. If you have not found the requested information in this section please submit a request to the Kaspersky Lab Technical support.

How to remove malware Worm.Win32.NeKav.a (eKav)

 ID Article: 3311    Other languages:  Polski  Русский  English      Views for 7 days 2    Last modified on 13.09.2011 16:52 Printable version

Useful references:
 

 

Worm.Win32.NeKav.a malware is a blackmailer-program which extorts money from the user, interferes with the normal work and has unauthorized access to removable drives. Worm.Win32.NeKav.a is a dynamically loaded library of Windows (PE-DLL file), has the size of 129536 bites, and is written on the Delphi language.

Worm.Win32.NeKav.a malware displays the message informing that some malicious software has been detected. The message contains a demand to send a message with a definite code to the number given in the message; sending a message will supposedly allow the user to continue work and to clean the system from viruses and Trojans.

Malware installation into the system

Worm.Win32.NeKav.a can install itself both under an administrator’s account and under a limited account. 

1. Installation of malware under administrator’s account

The malware performs the following actions:

  1. Malicious program selects a random file in the following folders:
    • %windir%\Inf 
    • %windir%\Help 
  2. Copies itself into an alternative NTFS-stream of the selected file 
  3. If by some reason the malware failed to copy itself into an NTFS-stream of the selected file, then it copies itself into the folder %windir%\system32 under a random name 
  4. To automatically start itself at the system startup, it writes itself into the system registry 
    • [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows] under the name "AppInit_Dlls"="<PATH_TO_MALICIOUS_DLL>"
  5. It provides load of the malicious library into all processes which use system library user32.dll 
  6. To start working instantly it restarts the system process ctfmon.exe 

2. Installation of malware under limited account

The malware performs the following actions:

  1. Copies itself under a random name into the %Temp% directory and creates a bat-file in the same folder with the following content: 
    • rundll32.exe <PATH_TO_MALICIOUS_DLL>,Open 
  2. To automatically start itself when the user enters the system, it writes itself into the registry key 
    • [HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Windows] under the name "load"="PATH_TO_BAT-FILE>" 
  3. The copied dll-file and a bat-file are encrypted with the help of EFS (Encrypting File System)

Spreading

The malware copies its body onto all available for record removable drives connected to the infected computer. Malware copy is created under the following name:

  • <NAME_OF_THE_INFECTED_REMOVABLE_DRIVE>:\Recycler\<RND>

For the malware to load each time the user opens an infected removable drive with Explorer, the malware puts the following file together with its executable file:

  • <name_of_the_infected_removable_drive >:\autorun.inf which contains the installation command rundll32.exe <PATH_TO_MALICIOUS_DLL>, Install

The files are created with the hidden attribute.

 

Features of malware infection: 

After the computer is infected with the malware a large message is displayed on the screen meaning "Internet Security detected malware on your computer" (sometimes instead of “Internet Security” the name “eKav Antivirus” can be used).

Then, the malware performs the following actions:

  1. Registry editor, task manager and system recovery are blocked 
  2. Launch of the installed anti-virus programs is blocked via group policies 
  3. All windows and processes whose headers contain the following words are closed/terminated:
    • BitDefender
    • eKav
    • AutoStart
    • x-cire
    • Antivirus
    • dispose
    • Anti-Malware
    • log
    • Startup
    • PTstartmon
    • Regedit
    • Internet Security
    • Ad-Aware
    • Total Commander
    • VirusTotal
    • PC Tools
    • SMS
    • Trojan
    • violate
    • antivirus
    • HiJack
    • Sysinternals
    • Quick Heal
    • Security parameters
    • virus
    • forum
    • F-PROT
    • Trend
    • OSAM
    • AVIRA
    • WinLock
    • Kaspersky
    • malware
    • Vba32
    • TrendMicro
    • AVG
    • a-squared
    • HijackThis
    • Nod32
    • AhnLab
    • Process Viewer
    • far
    • AVZ
    • Banner
    • Antispyware
    • LiveUpdate
    • accounts
    • trojan
    • Manipulation
    • Rootkit
    • ESET
    • Process Monitor
    • Zillya
    • McAfee
    • AnVir
    • Help
    • K7TotalSecurity
    • Registry
    • GMER
    • Security
    • Outpost
    • Process Explorer
    • Antimalware
    • Command prompt
    • Dr.Web
    • 4171
    • LiveInstall
    • DefenseWall
    • avast
    • 3649
    • Auto Update
    • rootkit
    • Malwarebytes
    • Registry editor
    • Spyware
    • Removal
    • F-Secure
    • CMC
    • Download Master
    • AutoRuns
    • spyware
    • Computer management
    • Termination
    • G Data
    • VIPRE
    • cmd.exe
    • group policy
  4. The malware removes and prevents repeated creation of files which refer to anti-virus programs:
    • With the names:
      • SpeProtector.exe
      • hidec.exe
      • K7SysMon.Exe
      • ccguard.dll
      • DrWeb32w.exe
      • AvastSS.scr
      • McTray.exe
      • avgio64.sys
      • avcenter.exe
      • Scanscr.dll
      • And etc. 
    • With the extensions:
      • vdb
      • cvd
      • scd
      • nup
      • kdc
      • dws
      • cnt
      • dwl
      • dta
      • ppl
      • Dsm
      • sig
      • avz
      • lrm
      • avp
      • avg
      • avc

Recommendations on how to remove the malware

If your computer was not protected with any anti-virus software and is now infected with Worm.Win32.NeKav.a, then in order to remove the malicious program you should perform the following actions:

  1. Use Kaspersky WindowsUnlocker. Kaspersky WindowsUnlocker is a free utility to fight ransom malware. The utility can be launched when your computer is booted from Kaspersky Rescue Disk. WindowsUnlocker disinfects registry (including user registry files) of all operating systems installed on the computer.
  2. Once the banner is removed, Kaspersky Lab specialists recommend to scan your computer for viruses. You can do it, for example, using a free utility Kaspersky Virus Removal Tool.
  3. In order to prevent future infections by the malware, install a real-time protection antivirus solution, for example, a Kaspersky Lab product. If you do not have a valid license for your Kaspersky Lab product, you can activate a 30-days trial version of the product:

 


 Did the provided info help you?

                       

 Give your detailed feedback.

 

Kaspersky Lab

Copyright © 1997-2013 Kaspersky Lab
Site map  |   Contact us  |   International Support Service  |  Send us a suspected virus

Stay connected