As of March 31, 2004, due to an increase in submission
rate, we have upgraded W32.Trance.1999@mm to a Category
3 level threat from a Category 2 threat.
The W32.Trance.1999@mm virus:
is a carefully crafted worm that remains resident
in the memory of an infected system
stays idle and is triggered when the system writes
or reads to a file ending with the MP3 suffix. It
will then search for an ID3 (v1/v2) tag and if the
"Genre" field has "Trance" selected
it will then release its payload and corrupt the music
file at 15 second intervals*
immediately begins to infect crucial Windows System
files and corrupts any past Windows XP System Restore
sessions preventing the user from recovering from
their pre-corrupted state
* Approximate - point of corruption
will vary with encoded quality & type used
Notes:
There is no way to fix a corrupted file - the data
is randomly shuffled using your system time as the
seed.
The virus has an MD5 value of 0x04871d17dbbd196d9dbd2011afc734dd.
Current information suggests this virus may be inspired
by Trance.1721
as it has a day-based trigger as well as one which is
file-based. W32.Trance.199@mm contains the text string:
"Trance Virus (c) 1999 by DJ Viral".
When W32.Trance.1999@mm is executed, it performs the
following actions:
Copies itself as %Windir%\WinTrance.exe (15,488
bytes).
Note: %Windir% is a variable. The worm locates
the Windows installation folder (by default, this
is C:\Windows or C:\Winnt) and copies itself to that
location.
Hooks onto rundll32 and any
processes that call upon it.
Creates a mutex named "_-oOaxX|-+O+-+a+-+K+-+e+-+N+-+f+-+O+-+l+-+D+-+|XxKOo-_",
which allows only one instance of the virus to remain
resident concurrently.
If the system date matches the 1st day of any month
it will attempt to perform a Denial of Service (DoS)
attack against the following sites between 17:00 and
21:00 (GMT):
www.ivibes.nu
www.tranceaddict.com
www.ets-global.org
PREVENTION
The best way to protect yourself is to set your MP3
files to be read-only so that the worm may not make
modifications to them.