Virus Database


I-Worm.Buzill.a

Description I-Worm.Buzill.a

Buzill is a worm virus spreading via the Internet as an attachment to infected emails. The worm itself is a Windows PE EXE file about 30KB in length (there is also a known variant that is compressed by UPX, (the compressed size is about 16KB). The Buzill worm is written in Visual Basic.
Infected messages have the following features:
The Subject field is either empty or randomly selected from the following variants:

Body text:
Here is the file I told you about. Dont tell anybody.Shhhhhhhh ;)

The Attachment file's name is randomly selected from the following variants:
gresge.exe slfklsbsklf.exe hsldnlg.exe
bsdkskshf.exe qewlwlef.exe qfdsdjl.exe
nlddoe.exe vdngdg.exe fsdhhgdd.exe
nfkrjhgr.exe lsjsdf.exe pqweopwrore.exe
wrretert.exe pjlfdg.exe nnbvcncld.exe

The worm activates from infected emails only if a user clicks on the attached file. If this action is taken the worm then installs itself to the system and runs its spreading routine and payload.
Installing
While installing the worm copies itself to the C: drive's root directory using a randomly selected name (please note the list of possible names for the file attachment above), and registers this file in the system registry auto-run key:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
BuzzKill = %worm file name%

Spreading
To send infected messages the worm uses MS Outlook and sends infected messages to all the addresses found in the Outlook address book.
Payload
On February 14th the worm displays the message:
IWorm.BuzzKill
Happy Birthday Joshua!!

and proceeds to delete all the files in the root directory of the C: drive.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.KillProt

Description Macro.Word.KillProt

This is an encrypted macro virus. It contains four macros: AutoOpen, FileSaveAs, FileOpen, ToolsMacro. It infects global macros area on AutoOpen and ToolsMacro, documents get infection on FileOpen and FileSaveAs.
The virus creates the "Count=" parameter in "Infector" section in system profiles and increases its value on each FileSaveAs call. On every tenth saving a document with new name the virus sets the password for that document:
WhatTheHell

On any other saving the virus converts document to template. On each AutoOpen the virus deletes the macros AutoExit, InstVer, ShellOpen (ScanProt-specific macros).

Macro.Word.KillSystem.a

Description Macro.Word.KillSystem.a

These are very dangerous viruses. They contain only one macro - Autoexec or AutoOpen depending on the virus version. On the 1st of any month these viruses delete the files: C:COMMAND.COM, C:AUTOEXEC.BAT, C:CONFIG.SYS. The viruses also contains texts in Chinese.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Dating
Advokat
BITUS AB
BME AUTOMOTIVE AB

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com