I-Worm.Klez.a
Description I-Worm.Klez.a This is a worm-virus that spreads via the Internet attached to infected e-mails. The worm itself is a Windows PE EXE file about 57-65Kb (depending on its version) in length, and it is written in Microsoft Visual C++. Infected messages have variable subjects and attachment names (see below). The worm uses an Internet Explorer security breach (IFRAME vulnerability) to start automatically when an infected message is viewed. In addition to spreading in the local network and in e-mail messages, the worm also creates a Windows EXE file with a random name starting with "K" (i.e., KB180.exe), in a temporary folder, writes the "Win32.Klez" virus in it, and launches the virus. The virus infects the majority of Win32 PE EXE files on all available computer disks. Start-up When an infected file is started, the worm copies itself to a Windows system folder with the krn132.exe name. Then it writes to registry the following key to start automatically with Windows: [HKLMSoftwareMicrosoftWindowsCurrentVersionRun] "Krn132" = "%System%Krn132.exe" where %System% is the name of the Windows system folder. Then the virus searches for active applications (anti-viruses, see the list below) and forces them to unload using a Windows "TerminateProcess" command: _AVP32 _AVPCC _AVPM ALERTSVC AMON AVP32 AVPCC AVPM N32SCANW NAVAPSVC NAVAPW32 NAVLU32 NAVRUNR NAVW32 NAVWNT NOD32 NPSSVC NRESQ32 NSCHED32 NSCHEDNT NSPLUGIN SCAN SMSS Replication: e-mail The worm uses SMTP protocol to send e-mail messages. It finds e-mail addresses in a WAB database and sends infected messages to these addresses. The subject of the infected message is selected randomly from the following list: Hello How are you? Can you help me? We want peace Where will you go? Congratulations!!! Don't cry Look at the pretty Some advice on your shortcoming Free XXX Pictures A free hot porn site Why don't you reply to me? How about have dinner with me together? Never kiss a stranger The message body is the following: I'm sorry to do so,but it's helpless to say sory. I want a good job,I must support my parents. Now you have seen my technical capabilities. How much my year-salary now? NO more than $5,500. What do you think of this fact? Don't call my names,I have no hostility. Can you help me? Attached file: Win32 PE EXE file with random name, which has either an ".exe" extension or a double extension: name.ext.exe The worm selects the filename (name.ext) using an original routine. It scans all available drives and finds there files with the following file-name extensions: .txt .htm .doc .jpg .bmp .xls .cpp .html .mpg .mpeg It uses one of the found filenames (name.ext) as the base name of an attachment, then it adds a second extension, ".exe". For example, "Ylhq.htm.exe", "If.xls.exe", etc. The worm inserts its own "From:" field into infected messages. Depending on the random counter, it inserts there either a real e-mail address, or a fake randomly generated address. An interesting feature of the worm is that before sending infected messages, the worm writes the list of found e-mail addresses in its EXE file. All strings in the worm's body (messages and addresses) are stored in an encrypted state. Replication: local and network drives The worm enumerates all local drives and network resources with written access and makes there its copy with a random name name.ext.exe (the name-generation routine is similar to one which is used to generate attachment names). After copying itself to network resources, the worm registers its copies on remote computers as system service applications. Payload On the 13th of even months, the worm executes a payload routine, which fills all files on all available victim s'computer disks with random content. These files can't be recovered and must be restored from a backup copy. Other versions There are several modifications of this worm. I-Worm.Klez.a-d are similar, and have minor differences. Klez.e-h are similar too, and have minor differences as well.
Check other viruses! Be aware! Use Antiviral Software
Rebel.1509
Description Rebel.1509
This is a dangerous memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of EXE files that are executed or opened. It deletes the files CHKLIST.MS, CHKLIST.CPS, and SMARTCHK.CPS. On the 16th of April, it decrypts and displays the following message: Happy Birthday KAORI! Dedicato a tutte le meravigliose ragazze giapponesi (C) BitLabs (The RebelBase) 1993, N. Italy.
Reboot.715
Description Reboot.715
This is a dangerous nonmemory resident parasitic virus. It searches for .COM files of the subdirectory tree, then it writes itself to the end of the file and writes to the beginning of the file the Jmp-Virus commands (MOV AX,FFF0h; JMP Loc_Virus). Depending on the system time the virus reboots the computer.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
HÄlsokuren Ama Arkivgatans TandvÅrd Ab Tumba FriskvÅrd C.c.c. Car Solutions A.j. Normans Kakel
|