I-Worm.Rastam
Description I-Worm.Rastam
This is Internet worm spreading with emails by affecting Eudora email client. The infected message arrives with the text "Help us go back to home!" at the end of the message body and attached DOS COM file "www.back2afrika.com" (the virus tries to cheat an user by disguising its .COM extension with URL-like name). If user activates the attached COM file, the worm gets control, creates EXE file with random name in temporary directory, and runs it. That EXE file is PE EXE file and contains main worm routine which registers worm text and attachment as Eudora auto-signature. As a result all outgoing mails will have worm text and attached COM file (see above) pasted to the end of the message. The worm code contains the text strings: RASTAMAN SOFTWARECLIENTSMAILEUDORASHELLOPENCOMMAND EUDORA.INI Use Signature Settings Help us go back to home! begin 644 www.back2afrika.com Haile Selassie is Jesus Christ! (tehporp sih si anceV dnA) Last string is "And Vecna is his prophet" written backwards. The known worm version has a bug and can't spread.
Check other viruses! Be aware! Use Antiviral Software
FartStorm.3794
Description FartStorm.3794
This is a very dangerous memory resident parasitic polymorphic virus. It hooks INT 21h, and writes itself to the end of COM and EXE files that are executed, closed or terminated. The virus does not infect the anti-viruses and utilities of TBAV, F-PROT, CHKDSK, as well as files that have the 'V' letter in their names, as well as COMMAND.COM. When an infected EXE file is opened or executed, the virus disinfects it and then re-infects. On Mondays that fall on 1, 3, 5, 7, and 9 of any month, the virus erases disk sectors on hard drive(s). If a key is pressed during this procedure, the virus displays the following message: The "FartStorm" coded by Demon Emperor >Big hello to Cmoskiller&Xorboot< Are you wild? Hey don'tall wait... let us talk... No? Be off lame fuckhead!
Fasola.2215
Description Fasola.2215
It is not a dangerous nonmemory resident parasitic virus. It searches for EXE-files, then writes itself to the end of the file. The virus looks for the string "JAREK=OFF" in Environment area, and performs no action if that string is found. Depending on the system date and time the virus displays the photo of some man (virus author?), and displays the message: Jarek Szczukowski wita !!!
The virus also contains the text strings: *.* *.exe Virus (C) Ja? Fasola'95 all rights reserved Tylko MKS-VIR to porz?dny program antywirusowy Nie daj si? naci?gn?c na jakie? Norton Antivirus albo inne badziewie w 'adnej graficznej oprawie Pamietajall MKS-VIR
? = characters not supported in this character set.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Stig Jansson Bygg GolvmÄstarna I SmÅland Aktiebolag Fuktab Aktiebolag TQI CONSULT VVS AB Renates Roliga Resor
|