I-Worm.Santa
Description I-Worm.Santa
This Internet virus-worm spreads via E-mail by sending infected messages from infected computers. While spreading, the worm uses MS Outlook and sends itself to adresses that are stored in the MS Outlook Address Book. The worm is written in the scripting language "Visual Basic Script" (VBS). It operates only on computers on which the Windows Scripting Host (WSH) is installed. In Windwos 98 and Windows 2000, WHS is installed by default. To spread itself, the worm accesses MS Outlook and uses its functions and address lists. That is available in Outlook 98/2000 only, so the worm is able to spread only in instance that one of these MS Outlook versions is installed. The worm arrives to a computer as an e-mail message with an attached VBS file, which is the worm itself. The message in the original worm version reads as follows: The Subject: News vom Weihnachtsmann [Name] Message body: Guten Tag, es ist bald Weihnachten. Und wie sieht's aus mit schönen Geschenken ? Hierzu ein Tip vom Weihnachtsmann: Unter www.leos-jeans.de gibt es die besten Geschenke im Web ! Das bedeutet absolut stressfreies Einkaufen, schnelle und unkomplizierte Lieferung, riesige Auswahl. Also nichts wie hin, und Frohe Weihnachten. Attached file name: XMAS.VBS Upon activation by a user (by double clicking on the attached file), the worm opens MS Outlook, gains access to the Address Book, obtains the first 50 addresses from each address list and sends messages with its attached copy to all of them. The message subject, body and attached file name are the same as above. The original worm version does not have any payload.
Check other viruses! Be aware! Use Antiviral Software
Feint
Description Feint
It is a harmless memory resident boot virus. It hooks INT 13h and writes itself to the boot sector of the floppy disks and to the MBR of the hard drive. The virus does not manifest itself in any way.
Feist.670
Description Feist.670
This is a dangerous memory-resident virus which by standard way hits COM- and EXE-files whenever they are started or opened. The virus also writes its TSR-copy to the address 9800:0000, changing nothing in the MCB fields. This may hang up the system. The infector hooks INT 21h.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Nylander, Mats Fredrik Magnus EngstrÖm LÖwenborg, Hanna Philipson VÄstra Svealand Bil Ab Helsingborgs HandtvÄtt Bil Hagmans Rep & Entreprenad
|