I-Worm.Bagle.ai
Description I-Worm.Bagle.ai
This worm spreads via the Internet as an attachment to infected messages and also via P2P networks. It is approximately 20 KB in size and packed using PEX. Installation Once launched, the worm copies itself to the Windows system directory as winxp.exe. It then registers this file in the system registry to ensure that this file is launched each time the system is started. [HKCUSOFTWAREMicrosoftWindowsCurrentVersionRun] "key"="%system%winxp.exe" The worm also creates the following files in the Windows system directory: winxp.exeopen winxp.exeopenopen winxp.exeopenopenopen winxp.exeopenopenopenopen Propagation The worm searches disks for files with extensions from the following lists. It sends itself to all addresses harvested from these files. adb asp cfg cgi dbx dhtm eml htm jsp mbx mdx mht mmf msg nch ods oft php pl sht shtm stm tbb txt uin wab wsh xls xml
It uses its own SMTP server to send messages. Infected messages Message header: Re: Versions of message body: >Animals >foto3 and MP3 >fotogalary and Music >fotoinfo >Lovely animals >Predators >Screen and Music >The snake Attachment name: Cat Cool_MP3 Dog Doll Fish Garry MP3 Music_MP3 New_MP3_Player Attachment name: com cpl exe scr zip The worm can send itself as a password protected ZIP archive. If it does this, the password will be shown in the message body. The password may be in text or graphical format. The worm will not send itself to addresses containing text strings from the list below: @avp. @foo @hotmail @iana @messagelab @microsoft @msn abuse admin anyone@ bsd bugs@ cafee certific contract@ feste free-av f-secur gold-certs@ google help@ icrosoft info@ kasp linux listserv local news nobody@ noone@ noreply ntivi panda pgp postmaster@ rating@ root@ samples sopho spam support unix update winrar winzip Propagation via P2P The worm searches disks for folders containing the text string shar. It then copies itself several times to these folders under the following names: ACDSee 9.exe Adobe Photoshop 9 full.exe Ahead Nero 7.exe Kaspersky Antivirus 5.0 KAV 5.0 Matrix 3 Revolution English Subtitles.exe Microsoft Office 2003 Crack, Working!.exe Microsoft Office XP working Crack, Keygen.exe Microsoft Windows XP, WinXP Crack, working Keygen.exe Opera 8 New!.exe Porno pics arhive, xxx.exe Porno Screensaver.scr Porno, sex, oral, anal cool, awesome!!.exe Serials.txt.exe WinAmp 5 Pro Keygen Crack Update.exe WinAmp 6 New!.exe Windown Longhorn Beta Leak.exe Windows Sourcecode update.doc.exe XXX hardcore images.exe Remote administration The worm opens port 1080 and another port chosen at random. It then tracks port activity. Other The worm is programmed to cease activity and self-destruct after 5th May 2006. It tracks the execution of most well-known antivirus products and firewalls and terminates these processes.. The worm's body contains a list of URLs. It attempts to download from these sites. At the moment of writing, none of the sites are functioning.
Check other viruses! Be aware! Use Antiviral Software
DHeart Family
Description DHeart Family
These are not dangerous not memory resident parasitic viruses. They search for executable files (by using internal masks "*.com" or "*.exe") and write themselves to the file end. After infection they display messages. "DHeart.452" infects EXE-files, it displays double hearts (03h ASCII) "DHeart.649" hits .COM-files except IBMBIO.COM and IBMDOS.COM. Depending on its internal counter it decrypts and displays the message: From Russia with love!
Dialogos.1350
Description Dialogos.1350
This is not dangerous nonmemory resident parasitic virus. They search for the files: C:COMMAND.COM C:DOSCOMMAND.COM C:MSDOSCOMMAND.COM C:DRDOSCOMMAND.COM Then for *.COM files, then write themselves to the end of the file. On June 10th they display the message and halt the computer: 1984-1994 10 Aniversario de DIALOGOS-3 de RNE. Dedicado a Ramon por estos 10 anos, y por venir a la SALA-4. Buscad la belleza es la unica protesta que merece la pena, en este asqueroso mundo. 10/03/95 Valencia ESPANA
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Mexican Houses Top Ten Franchises 2007 Gutschein Verschenken Hotels Hungary Cardinal Calling Card
|