Full Version of this article can be found here

re_file.exe

re_file.exe


What is it?
re_file.exe is associated with the w32.beagle.ar@mm mass mailing worm.

What does it do?
W32.Beagle.AR@mm is a mass-mailing worm that uses its own SMTP engine to spread. The email attachment is a downloader, similar to the Mitglieder family of Trojans, that downloads the worm from an external source.

When W32.Beagle.AR@mm runs, it does the following:
  1. Creates seven mutexes with the following names, which prevent some variants of the W32.Netsky@mm family of worms from running:
    • MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D
    • 'D'r'o'p'p'e'd'S'k'y'N'e't'
    • _-oOaxX|-+S+-+k+-+y+-+N+-+e+-+t+-|XxKOo-_
    • [SkyNet.cz]SystemsMutex
    • AdmSkynetJklS003
    • ____--->>>>U<<<<--____
    • _-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_
  2. Creates the following files:
    • %System%awindo.exe.
    • %System%awindo.exeopen (A copy of the worm with randomly appended data.)
    • %System%awindo.exeopenopen (A copy of the worm with randomly appended data.)
    • %System% e_file.exe
  3. Adds a value:


    "bawindo"="%System%awindo.exe"

    to the registry key:

    HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun
Attempts to create copies of itself in any folder that contains the characters "shar". The files will have the following file names:
More info and Removal
@symantec