I-Worm.Funny
Description I-Worm.Funny
This is an Internet worm written in the scripting language "Visual Basic Script" (VBS). The worm uses MS Oulook to spread its copies by e-mail. Upon activation, the worm sends its copy to all recipients from the MS Outlook address list. The infected message has only the subject line "Funny story" and the attached file "FUNNY_STORY.HTM.vbs" that is the worm itself. Depending on system settings, the actual extension of the attached file (.vbs) may not be displayed. The worm carries the Trojan program code of Trojan.PSW.Hooker. After spreading, the worm writes this program onto a disk and starts it.
Check other viruses! Be aware! Use Antiviral Software
Cartier.1056
Description Cartier.1056
Cartier.1056 is a dangerous not memory resident parasitic virus. It searches for .COM-files and writes itself to their ends. It erases the FAT of the C: drive and displays: +----------------------------------------------------------------------------+ ¦ Don't panic it, I am just a virus named [Cartier]. Nice to meet you ! ¦ ¦ You are so dirty to get software without any payments ! I don't like it ! ¦ ¦ So, I destory all of your datas in the hard disk now ! Feel so good ! ¦ +----------------------------------------------------------------------------¦ ¦I wish you like that ! ¦ What about a drink ? ¦ See you next time ! ¦ +----------------------------------------------------------------------------+
Cascade.1491
Description Cascade.1491
This is a memory resident virus. Its body except for the beginning (first 32 bytes) is encoded. As a key the length of the infected file is used. That is why two strains of the same virus in most cases will coincide only in the first 32 bytes. As an infected program is executed, the control of the JMP command is transferred to the beginning of the virus. By first commands the virus determines the length of the source file and deciphers its body. On creating its memory-resident copy the virus: copies its body into the highest addresses of the memory; moves the body of the main program into the highest addresses of the memory; moves the virus body into cleared area above the main program body; sets INT 1Ch, 21h, 28h to its own copy. ƒ all ƒ ƒ ... ƒ ƒ ... ƒ ƒ ... ƒ +---------ƒ +---------ƒ +---------ƒ +---------ƒ ƒProgram ƒ ƒProgram ƒ--+ ƒFree ƒ +-->ƒVirus ƒ ƒ ƒ ƒ ƒ ƒ ƒmemory ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ +---------ƒ ƒ +---------ƒ +---------ƒ +---------ƒ +-->ƒProgram ƒ ƒ ƒProgram ƒ ƒVirus ƒ--+ ƒVirus ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ +---------ƒ ƒ +---------ƒ +---------ƒ ƒ +---------ƒ ƒ ... ƒ +-->ƒVirus ƒ ƒVirus ƒ--+ ƒ ... ƒ ƒ(copy) ƒ ƒ ƒ +---------ƒ +---------ƒ ƒ ... ƒ ƒ ... ƒ
The virus affects only COM files as it's loaded into the memory for execution. Infection is carried out by standard method. Most widely spread versions of this virus does not reinfect files. The virus changes interrupt vectors 1Ch, 21h and 28h. It also produces a specific video-effect: crumbling down of letters on the screen; does not have destructive functions. Sometimes it displays the message: IL SISTEMA è FOTTUTO!! S.E.K. VIRUS Made in ITALY RM 5iD G.Ferraris 90/91 (c) Then it erases the disk sectors. It also deletes CHKLIST.CPS file.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|