Virus Database


I-Worm.CoolNow

Description I-Worm.CoolNow

This is a virus-worm that spreads via the Internet using MSN Messenger (instant messaging program). The worm itself is a JS-script (Java Script) located in an HTML file. It sends messages that contain an URL pointing to an infected Web page.
When the worm is executed, it obtains the MSN Messenger contact list, and sends to all its recipients the following message:
"URGENT - Go to http://www.rjdesigns.co.uk/cool Now"
This address points to an HTML-file, which contains the worm's body.
After sending infected e-mail messages, the worm uses a script, which is located at the same site, to send a e-mail message to "jonathansmith288@hotmail.com" . This message contains the IP address of the infected computer, and redirects the user to the following address:
"http://www.rjdesigns.co.uk/cool/go.htm"
The worm doesn't contain any payloads.

Check other viruses! Be aware! Use Antiviral Software

FP.332

Description FP.332

It is a very dangerous nonmemory resident overwriting virus. It searches for .COM files, then overwrites them. Before return to DOS the virus leaves in the memory a TSR program that hooks INT 8 (timer) and depending on its counter beeps and stuffs the string into keyboard buffer:
Fisher Price 96

The virus also contains the text strings:
Ok.
*.COM
Dos Auto-exctractible archive,

Fr.1013

Description Fr.1013

It's a harmless memory resident parasitic virus. It hooks INT 21h and infects by a standard manner COM- and EXE-files on their execution or opening. It contains the internal word "FR".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com