Virus Database


I-Worm.Nevezed (aka Never)

Description I-Worm.Nevezed (aka Never)

Nevezed is a worm virus spreading via Microsoft Outlook. The worm itself is a Java Script file about 4KB in size and written in Java.
Installation
During installation the worm copies itself to the Windows system StartUp directory under the name "StartUp.js" and the Windows System directory under the name "CmdWsh32.js". It them registers this later file in the system registry as a java-class file. The worm also creates a backup copy of itself in the root directory of other drives.
Spreading: Email
To send infected messages the worm uses MS Outlook to send messages to all the addresses found in a victim's Outlook address book.
Infected messages sent by the worm have various subject titles. Possible subject titles could be:
Hello name
Hey name
Fwd: Hey You!
Fwd: Check this!
Fwd: Just Look
Fwd: Take a look!
Fwd: Loop at this!
Fwd: Check this out!
Fwd: It's Free!
Fwd: Look!
Fwd: Free Mp3s!
Fwd: Here you go!
Fwd: Have a look!
Look name!
Fwd: Read This!

Message body text is as follows:
Hello!
Check out this great list of mp3 sites that I included in the attachments! I can get any Mp3 file that I want from these sites, and its free! And please don't be greedy! forward this email to all the people that you consider friends, and Let them benefit from these Mp3 sites aswell! Enjoy !
Infected messages contain one of following attachments:
Free_Mp3s.js
Fwd_Mp3s.js
Mp3_Sites.js
Mp3_Web.js
Mp3_List.js
Mp3_Pages.js
Web_Mp3s.js
Mp3-Sites.js
Fwd-Mp3s.js
Mp3-Fwd.js
Fwd-Sites.js

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Counter

Description Macro.Word.Counter

This stealth macro virus. It does not manifest itself in any way. It contains six macros: FileExit, FileSave, FileClose, Generation, ToolsMacro (stealth), FileTemplates. The virus infects the global macros area on Word exiting, saving or closing documents (FileExit, FileSave, FileClose). It infects documents on their saving or closing (FileSave, FileClose). The virus keeps its generation counter in the descriptor for macro "Generation".

Macro.Word.Crema

Description Macro.Word.Crema

This macro virus contains four macros: aUtoopen, CREMA, HerramMacro, archivoplantillas. It replicates itself on opening documents (AutoOpen). Depending on system random counter the virus displays the Message/DialogBoxes:
Crema Virus
Bl4cK Sc4v3ng3R - PERU
Tu tambien eres hincha!
Buena Crema!
SOY CREMA!!!! :-)
ESE ES LA U!!!!!
El mejor de los equipos!!

The virus does not exits DialogBox up to one of the strings is entered: "universitario", "lolo", "peru", "sc4v3ng3r".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com