Fandom

Malware Wiki

CoolNotepad

1,319pages on
this wiki
Add New Page
Comments0 Share


CoolNotepad is an email worm that propagates through both Microsoft Outlook and mIRC, similar to the LoveLetter worm. The infection will start with the user receiving an infected email that may look like this:

Subject

Cool Notepad Demo

Message body

Hey check out this text file I sent it will do something neat in notepad. Enjoy :)

Attachments

COOL_NOTEPAD_DEMO.TXT.vbs

As common file extensions are hidden by default, the user will simply see "COOL_NOTEPAD_DEMO.TXT", and thus believe it to be simply a text document, and thus may open it without suspecting it to be malicious.

The worm, like many others, will search for contacts in Outlook's address book, sending copies of the email above with the worm attached. It can also spread through IRC, infecting channels which will attempt to send the file to users who attempt to join it.

The worm will add itself to the system registry such that it executes on startup:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun

COOL_NOTEPAD_DEMO = <FileName>

It will also edit the registry such that all shortcuts on the desktop are hidden:

HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer
NoDesktop = 1

SourcesEdit

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.