Virus Database


I-Worm.Bagle.ai

Description I-Worm.Bagle.ai

This worm spreads via the Internet as an attachment to infected messages and also via P2P networks.
It is approximately 20 KB in size and packed using PEX.
Installation
Once launched, the worm copies itself to the Windows system directory as winxp.exe. It then registers this file in the system registry to ensure that this file is launched each time the system is started.
[HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun]
"key"="%system%winxp.exe"
The worm also creates the following files in the Windows system directory:
winxp.exeopen
winxp.exeopenopen
winxp.exeopenopenopen
winxp.exeopenopenopenopen
Propagation
The worm searches disks for files with extensions from the following lists. It sends itself to all addresses harvested from these files.
adb
asp
cfg
cgi
dbx
dhtm
eml
htm
jsp
mbx
mdx
mht
mmf
msg
nch
ods
oft
php
pl
sht
shtm
stm
tbb
txt
uin
wab
wsh
xls
xml


It uses its own SMTP server to send messages.
Infected messages
Message header:
Re:
Versions of message body:
>Animals
>foto3 and MP3
>fotogalary and Music
>fotoinfo
>Lovely animals
>Predators
>Screen and Music
>The snake
Attachment name:
Cat
Cool_MP3
Dog
Doll
Fish
Garry
MP3
Music_MP3
New_MP3_Player
Attachment name:
com
cpl
exe
scr
zip
The worm can send itself as a password protected ZIP archive. If it does this, the password will be shown in the message body. The password may be in text or graphical format.
The worm will not send itself to addresses containing text strings from the list below:
@avp.
@foo
@hotmail
@iana
@messagelab
@microsoft
@msn
abuse
admin
anyone@
bsd
bugs@
cafee
certific
contract@
feste
free-av
f-secur
gold-certs@
google
help@
icrosoft
info@
kasp
linux
listserv
local
news
nobody@
noone@
noreply
ntivi
panda
pgp
postmaster@
rating@
root@
samples
sopho
spam
support
unix
update
winrar
winzip
Propagation via P2P
The worm searches disks for folders containing the text string shar. It then copies itself several times to these folders under the following names:
ACDSee 9.exe
Adobe Photoshop 9 full.exe
Ahead Nero 7.exe
Kaspersky Antivirus 5.0
KAV 5.0
Matrix 3 Revolution English Subtitles.exe
Microsoft Office 2003 Crack, Working!.exe
Microsoft Office XP working Crack, Keygen.exe
Microsoft Windows XP, WinXP Crack, working Keygen.exe
Opera 8 New!.exe
Porno pics arhive, xxx.exe
Porno Screensaver.scr
Porno, sex, oral, anal cool, awesome!!.exe
Serials.txt.exe
WinAmp 5 Pro Keygen Crack Update.exe
WinAmp 6 New!.exe
Windown Longhorn Beta Leak.exe
Windows Sourcecode update.doc.exe
XXX hardcore images.exe
Remote administration
The worm opens port 1080 and another port chosen at random. It then tracks port activity.
Other
The worm is programmed to cease activity and self-destruct after 5th May 2006.
It tracks the execution of most well-known antivirus products and firewalls and terminates these processes..
The worm's body contains a list of URLs. It attempts to download from these sites. At the moment of writing, none of the sites are functioning.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Alliance

Description Macro.Word.Alliance

This virus contains only one macro in infected documents - AutoOpen, but while infecting the system it copies it to two macros - AutoOpen and AutoNew. As a result, the virus infects the system on opening an infected document, and infects the documents that are opened or created.
The virus sets Subject in the FileSummaryInfo to:
You Have Been Infected by the Alliance

Macro.Word.Anak

Description Macro.Word.Anak

This is an encrypted macro virus. It contains four original macros that are copied to five ones while infecting documents and NORMAL.DOT:
Documents NORMAL.DOT
Macro1 anakAE AutoExec
Macro2 AutoOpen anakAO
anakAO
Macro3 anakSA FileSave
anakSA
Macro4 anakSMU anakSMU

The virus infects the global macros area on opening an infected document (AutoOpen) and writes itself to document on saving them (FileSave).
The virus defines new short cut key "Shift-Ctrl-F" and associates it with Tools/Customize menu. To hide its macros (stealth feature) the virus removes the File/Templates, Tools/Macros and Tools/Customize menus.
Starting from 25th of any month, starting from 14:00 the virus creates new template, inserts the text into there:
alli n t r o d u c i n g...
anakSMU
Semarang, March 1997

The virus then registers itself in the system. To do that it creates the ANAKSMU.BAT file, writes the commands to there and executes it:
@ECHO OFF
REM ---------------------------------------------------------
REM anakSMU wont destroy your REGEDIT, Just wanna be there :)
REM email: anakSMU@TheOffice.net"
REM ---------------------------------------------------------
ECHO REGEDIT4 > anakSMU.REG
ECHO [HKEY_CURRENT_USERSoftwareanakSMU] >> anakSMU.REG
ECHO [HKEY_CURRENT_USERSoftwareanakSMUanakSMU@TheOffice.net] >> anakSMU.REG
ECHO [HKEY_CURRENT_USERSoftwareanakSMU18.090 - Semarang] >> anakSMU.REG
START /MIN REGEDIT anakSMU.REG
EXIT

The virus then displays the MessageBox:
anakSMU
Yeah!, I wish I were anakSMU

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com