I-Worm.Desos.a
Description I-Worm.Desos.a Desos is an Internet worm that spreads as an attachment to infected e-mail messages. Messages sent by the worm contain various subjects, bodies and attachment names. Possible message subjects: Seduccion Humano Musica Mujer Hombre Confesion Infidelidad Belleza Relaciones casuales Tus deseos Mi secreto La clave Enojo Perdon Responde! Cita Papelon Renuncio Monstruo Joven
Possible attachment names: s_CAP3.EXE HUMANO.EXE MUSIC.EXE MUJER.EXE HOMBRE.EXE CONFESION.EXE INFIEL.EXE BELLEZA.EXE LISTArc.EXE DESEOS.EXE SECRETO.EXE CLAVE.EXE YO.EXE FEOS.EXE PASION.EXE CITA2.EXE GORDA.EXE CUERPO.EXE MONSTRUO.EXE JOVEN.EXE
Possible message bodies: Cap.3 El arte de provocar. El Ser Humano que pudiste ser. Esta es la musica que te prometi. La mujer mas bellaall Un hombre entero. ?Ya sabes que fui yo?. Las imagenes de tu infidelidad. ?No estas conforme con tu apariencia? Esta es la lista para esta semana. Si te conforman, puedo enviar mas. Recorda tu promesa! No la vuelvas a perder, no abuses. Cuando veas esto, se te pasa. Crei que ya lo habia enviado. Nunca respondiste. No seas cruel. Me gusto lo que enviaste. Si te gusta, arreglamos. Te dije que es demasiado gorda. Mira! No puedo mejorarlo, ya es perfecto. Ahora te creo. Pobre mujer! Disculpa, sos demasiado joven para mi.
Installation The worm copies itself to the Windows directory under the name "ESMTP.EXE", and write the following registry value to have its copy execute upon reboot: HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun Esmtp=(Windows directory path)Esmtp.exe
Replication: via e-mail Desos searches for e-mail addresses in the Windows Address Book (WAB), and files that have the .HT* extension (where * means any string) in the Windows Temporary directory. It then sends infected messages to these addresses. To send infected messages it uses a direct connection to the default SMTP Server.
Check other viruses! Be aware! Use Antiviral Software
Nocopy.3685
Description Nocopy.3685
These are not dangerous memory resident encrypted parasitic viruses. They hook INT 20h, 21h, 2Fh and write themselves to the end of EXE files that are accessed. They create file-dropper NOCOPY.COM and insert the string "C:NOCOPY" to the beginning of C:AUTOEXEC.BAT file. They correct MBR of hard drive so that while loading from that disk the virus receives the BIOS address of INT 13h.
NoDbf.1000
Description NoDbf.1000
It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are executed or opened. The virus does not infect files with names that are finished with digit or "EB" or "ST" (WEB, AIDS). The virus also compares file name extension with "DBF" and cancels attempts to open these files.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Dedikert Server Kjøkkenfornyeren Eclipse Rcp Build Cornice Box Italy India Calling
|