Virus Analysis:

Troj/Sysbug-A

Aliases: Backdoor-CAG
Type: Trojan

Description: Troj/Sysbug-A is a Trojan that retrieves system information and allows unauthorised access to the compromised computer. This Trojan horse has been distributed in the form of an email with the following characteristics:

From: james2003@hotmail.com

Subject line: Re[2]: Mary

Message text:

Hello my dear Mary,

I have been thinking about you all night. I would like to apologize for the other night when we made beautiful love and did not use condoms. I know this was a mistake and I beg you to forgive me.

I miss you more than anything, please call me Mary, I need you. Do you remember when we were having wild sex in my house? I remember it all like it was only yesterday. You said that the pictures would not come out good, but you were very wrong, they are great. I didn't want to show you the pictures at first, but now I think it's time for you to see them. Please look in the attachment and you will see what I mean.

I love you with all my heart, James.

Attached file: Private.zip (contains wendynaked.jpg.exe)

Troj/Sysbug-A will copy itself to the Windows folder as sysdeb32.exe and adds the following registry entry to ensure it gets run at system logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\SystemDebug

Troj/Sysbug-A creates the files svc.sav in the Windows folder and C:\temp35.txt. These files are not malicious and can simply be deleted.

http://www.sophos.com/virusinfo/analyses/trojsysbuga.html