Virus Database


I-Worm.Bagle.e

Description I-Worm.Bagle.e
This worm spreads via the Internet as a file attached to infected emails. The worm itself is a PE EXE file of approximately 17KB, packed using PEX. The unpacked file is approximately 27KB in size.
Infected messages have the following characteristics:
Message header (chosen from the list below):
Accounts department
Ahtung!
Camila
Daily activity report
Ello!
Flayers among us
Freedom for everyone
From Hair-cutter
From me
Greet the day
Hardware devices price-list
Hello my friend
Hi!
Jenny
Jessica
Looking for the report
Maria
Melissa
Monthly incomings summary
New Price-list
Price
Price list
Pricelist
Price-list
Proclivity to servitude
Registration confirmation
The account
The employee
The summary
USA government abolishes the capital punishment Weekly activity report Wellall
You are dismissed
You really love me? he he
Message body (chosen from the list below):
Cya
Empty
Everything inside the attach
Look it through
Request
Response
Subj
Attachment:
The attachment is a zip file which a name consisting of a random combination of a, b, and c (e.g. cdda.zip). Inside the .zip file is an .exe file with a random name, containing a text file icon.
Installation
Following installation, the worm copies itself and its components to the Windows system directory, under the names "i1ru74n4.exe", "godo.exe", "ii455nj4.exe", and "i1ru74n4.exeopen". It registers "i1ru74n4.exe" in the system registry auto-run key:
[HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun]
"rate.exe" = "%system%i1ru74n4.exe"
The worm also creates the registry key:
[HKCUSOFTWAREDateTime4]
and saves its variables in the key.
The worm attempts to connect to several sites and save information about the infected victim computer on these sites.
The worm also creates a mutex imain_mutex to flag its presence in memory.
Propagation
The worm searches for files with the following extentions:
adb
asp
cfg
dbx
eml
htm
html
mdx
mmf
nch
ods
php
pl
sht
txt
wab
harvests email addresses, and then sends itself to all addresses found. To send messages, the worm uses its own SMTP server.
Remote administration
The worm opens port 2745 and tracks port activity. The backdoor function makes it possible to remotely execute commands and download files to the victim machine.
Other
The worm attempts to counteract antivirus programs by terminating the following processes:
ATUPDATER.EXE
AUPDATE.EXE
AUTODOWN.EXE
AUTOTRACE.EXE
AUTOUPDATE.EXE
AVLTMAIN.EXE
AVPUPD.EXE
AVWUPD32.EXE
AVXQUAR.EXE
CFIAUDIT.EXE
DRWEBUPW.EXE
ICSSUPPNT.EXE
ICSUPP95.EXE
LUALL.EXE
MCUPDATE.EXE
NUPGRADE.EXE
OUTPOST.EXE
UPDATE.EXE
The worm is programmed to cease propagation after 25th March 2004.

Check other viruses! Be aware! Use Antiviral Software

Black.1000.b

Description Black.1000.b

This is a benign non-memory resident encrypted parasitic virus. It searches for executable files in the current directory and writes itself to the end of the file. It infects both COM and EXE files.
On November, 29th the viruses display the message:
Your computer is breaking . . .
and halt the computer.
It also contains the text:
Black Hacker's revenge.

BlackAdder.1015

Description BlackAdder.1015

It is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM- and EXE-files that are accessed. The virus does not infect the files with the names: *AV.*, *AN.*. The virus deletes the CHKLIST.MS files, contains the text strings:
Black Adder(C)94/95
-made in Italy by Doctor Who-
-Life's a journey not a destinationall-
CHKLIST MS
Wh

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Properties In Portugal
Software Downloads
City Flat Anbieter
Free Wireless Service Plus Residuals!!
Juegos De Naruto

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com