Virus Database


I-Worm.Calil

Description I-Worm.Calil

Calil is an Internet worm spreading via the Internet as an attachment to infected email messages.
The worm sends out messages with the following properties:

Subject: FW:FW: LILAC project video attach
Attachment name: LILAC_WHAT_A_WONDERFULNAME.avi
Attachment size: 12208 bytes
Message body: Things that the govt. dont want you to know

Installation
When the worm is launched on a computer for the first time, it tries to copy itself to the following hard coded locations:

c:win98 empLILAC_WHAT_A_WONDERFULNAME.avi c:windows empLILAC_WHAT_A_WONDERFULNAME.avi.exe c:win95 empLILAC_WHAT_A_WONDERFULNAME.avi.exe c:winnt empLILAC_WHAT_A_WONDERFULNAME.avi.exe c:winme empLILAC_WHAT_A_WONDERFULNAME.avi.exe c:winxp empLILAC_WHAT_A_WONDERFULNAME.avi.exe
Calil launches a copy of itself, automatically upon the restart of Windows by writing the following registry value:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun Lilac=(one of the paths specified above)
Next the worm shows a fake error message:
Windows Error54: Media Player not installed correctly

Replication
The worm gets e-mail addresses from the Windows and Outlook address books, and sends infected messages to these addresses. It uses Outlook to send infected messages. Other
Calil changes the system registered owner information by writing the following registry values:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersion RegisteredOwner=xEnOcrAtEs LegalNoticeCaption=Owned by: LegalNoticeText=Owned by: xEnOcrAtEs
This forces Windows to show the following message when starting:
Owned by: xEnOcrAtEs

Check other viruses! Be aware! Use Antiviral Software

Scotch.2611

Description Scotch.2611

It is not a dangerous nonmemory resident parasitic virus. It searches for .COM files and writes itself to the end of the file. It displays the messages, then waits for a keystroke:
Donner un nombre entre 0 et pour exécuter le programme demandé:
Bravo,vous êtes la nouvelle victime du SCOTCH' virus!
Désolé,j'avais choisi le nombre all

Scoundrel

Description Scoundrel

It is not a dangerous memory resident parasitic polymorphic virus. It traces and hooks INT 21h, then it infects COM and EXE files that are accessed. On renaming, opening, loading into the memory (function 4B01h) the virus temporary disinfects the infected files. Sometimes it displays the message:
SoftPecker v.1 (C) 1992 by ScoundrelSoft - 'Your pleasure is our business'

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com