I-Worm.CoolNow
Description I-Worm.CoolNow
This is a virus-worm that spreads via the Internet using MSN Messenger (instant messaging program). The worm itself is a JS-script (Java Script) located in an HTML file. It sends messages that contain an URL pointing to an infected Web page. When the worm is executed, it obtains the MSN Messenger contact list, and sends to all its recipients the following message: "URGENT - Go to http://www.rjdesigns.co.uk/cool Now" This address points to an HTML-file, which contains the worm's body. After sending infected e-mail messages, the worm uses a script, which is located at the same site, to send a e-mail message to "jonathansmith288@hotmail.com" . This message contains the IP address of the infected computer, and redirects the user to the following address: "http://www.rjdesigns.co.uk/cool/go.htm" The worm doesn't contain any payloads.
Check other viruses! Be aware! Use Antiviral Software
Congratulations
Description Congratulations
It's a dangerous not memory resident parasitic encrypted virus. It searches for EXE-files and writes itself at their ends. In some cases it deletes the file instead of infection. Depending on its generation number it displays the message: Congratulations, you have a virus
Constructor.BAT.BWG
Description Constructor.BAT.BWG
Constructor creates batch payload programs. It is written in Basic for DOS. It creates payload programs of the following types: internet worms mIRC worms pIRC worms installing to the win.ini installing to the system registry startup key installing to the startup directory deletes antivirus programs Constructor inserts the following comment in the beginning of batch files: REM generated with BATCH WORM GENERATOR x.xx
|