# VBS.Celeron.B.Worm

Discovered:
30 December 2002
Updated:
13 February 2007
Systems Affected:
Windows

The VBS.Celeron.B.Worm attempts to spread itself through the KaZaA file-sharing network. The existence of the Celeron.txt file is an indication of a possible infection.

### Antivirus Protection Dates

• Initial Rapid Release version 31 December 2002
• Latest Rapid Release version 28 September 2010 revision 054
• Initial Daily Certified version 31 December 2002
• Latest Daily Certified version 28 September 2010 revision 036
• Initial Weekly Certified release date 31 December 2002
When the VBS.Celeron.B.Worm runs, it does the following:
1. Displays eight fake messages. The text in the title bar of the messages is always Norton AntiVirus.

The messages are:
1. This Program Always Will Protect Your PC
2. Please Turn Off Any Kind Of Antivirus For Best Results WWW.Symatec.com
3. This Program remove 5 different virus
2. Copies itself as these files:
• A:\Help.vbs
• C:\Windows\System32\DVD32.vbs
• C:\Windows\System\Hotmail.vbs
• C:\Windows\Help\Ayuda.vbs
• C:\Windows\Help\Scrip.vbs
• C:\Windows\Help\ANA.vbs
• C:\Program Files\Kazaa\My Shared Folder\Cristina.jpg.vbs
• C:\Program Files\Kazaa\My Shared Folder\Lesbianas.jpg.vbs
• C:\Program Files\Kazaa\My Shared Folder\Sexo.jpg.vbs
• C:\Program Files\Kazaa\My Shared Folder\Video porno.jpg.vbs
• C:\Program Files\Kazaa\My Shared Folder\Anal.jpg.vbs
• C:\Program Files\Kazaa\My Shared Folder\Britney.jpg.vbs
• C:\Program Files\Kazaa\My Shared Folder\Cristina.jpg.vbs
• C:\Program Files\Kazaa\My Shared Folder\Norton.vbs
• C:\Program Files\Kazaa\My Shared Folder\Hackers.vbs
• C:\Program Files\Kazaa\My Shared Folder\Hotmail.vbs
• C:\Program Files\Kazaa\My Shared Folder\Programa para hackear.vbs
• C:\Program Files\Kazaa\My Shared Folder\Age.exe.vbs
• C:\Program Files\Kazaa\My Shared Folder\Documento hacker.vbs
• C:\Program Files\Kazaa\My Shared Folder\Como hackear.txt.vbs
• C:\Program Files\Kazaa\My Shared Folder\Sexo.vbs
• C:\Program Files\Kazaa\My Shared Folder\Fotos.vbs
• C:\Program Files\Kazaa\My Shared Folder\sexoyamor.txt.vbs
• C:\Program Files\Kazaa\My Shared Folder\Visual.vbs
• C:\Program Files\Kazaa\My Shared Folder\Visual Basic 6.vbs
• C:\Program Files\Kazaa\My Shared Folder\Word.vbs
• C:\Program Files\Kazaa\My Shared Folder\Windows.vbs
• C:\Program Files\Kazaa\My Shared Folder\Xp.vbs
• C:\Program Files\Kazaa\My Shared Folder\Putas.vbs
• C:\Program Files\Kazaa\My Shared Folder\Norton Quick remove.vbs
• C:\Program Files\Kazaa\My Shared Folder\Celeron Remove.vbs
• C:\Program Files\Kazaa\My Shared Folder\Anti Celeron Virus.vbs
3. May copy itself as one of the following:
• A:\SEX SEX.jpg.vbs
• A:\Cristina Porn.jpg.vbs
• A:\Porn.vbs

Run C:\WINDOWS\system32\DVD32.vbs
Windll C:\WINDOWS\system\Hotmail.vbs

to the registry key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm runs when you restart Windows.
5. Creates the text file C:\Celeron.txt, which is 56 bytes in length. This file is not viral in itself, and Symantec antivirus products do not detect it as such.
6. Deletes the following files, if they exist:
• C:\Autoexec.bat
• C:\Program Files\Norton AntiVirus\Navstub.exe
• C:\Program Files\Norton AntiVirus\Navw32.exe
• C:\Program Files\Norton AntiVirus\Navapsvc.exe
• C:\Program Files\Symantec\LiveUpdate\Ndetect.exe

These instructions are for all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
• On Windows 95/98/Me systems, if the worm deleted the Autoexec.bat file, replace it from a clean backup.
• If the worm deleted the Notepad.exe file, replace it from a clean backup, or re-install it.
• If you are not able to start Norton AntiVirus or run LiveUpdate because the worm deleted some of its files, re-install Norton AntiVirus before you can begin the removal procedure.
1. Update the virus definitions.
2. Run a full system scan and delete all the files detected as the VBS.Celeron.B.Worm.
3. Delete the values

Run C:\WINDOWS\system32\DVD32.vbs
Windll C:\WINDOWS\system\Hotmail.vbs

from the registry key

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
For further details, read the following instructions.

Updating the virus definitions
Symantec Security Response fully tests all the virus definitions for quality assurance before they are posted to our servers. There are two ways to obtain the most recent virus definitions:
• Running LiveUpdate, which is the easiest way to obtain virus definitions. These virus definitions are posted to the LiveUpdate servers once each week (usually on Wednesdays), unless there is a major virus outbreak. To determine whether definitions for this threat are available by LiveUpdate, look at the Virus Definitions (LiveUpdate) line at the top of this writeup.
• Downloading the definitions using the Intelligent Updater. The Intelligent Updater virus definitions are posted on U.S. business days (Monday through Friday). You should download the definitions from the Symantec Security Response Web site and manually install them. To determine whether definitions for this threat are available by the Intelligent Updater, look at the Virus Definitions (Intelligent Updater) line at the top of this writeup.

The Intelligent Updater virus definitions are available here.

Scanning for and repairing the infected files
1. Start your Symantec antivirus software and make sure that it is configured to scan all the files.
2. Run a full system scan.
3. If any files are detected as infected with VBS.Celeron.B.Worm, click Delete.

Deleting the values from the registry

CAUTION : Symantec strongly recommends that you back up the registry before you make any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify the specified keys only. Read the document, "How to make a backup of the Windows registry ," for instructions.
1. Click Start, then click Run. (The Run dialog box appears.)
2. Type regedit, then click OK. (The Registry Editor opens.)
3. Navigate to the key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run.
4. In the right pane, delete the values:

Run C:\WINDOWS\system32\DVD32.vbs
Windll C:\WINDOWS\system\Hotmail.vbs
5. Exit the Registry Editor.

Writeup By: Yana Liu