I-Worm.Stator
Description I-Worm.Stator
This is an Internet worm that spreads via infected e-mails. The worm is able to spread only from computers that have TheBat! e-mail client installed. The worm obtains victims' e-mail addresses from TheBat! database. To send itself from an infected computer, the worm uses SMTP protocol and connects to the smtp.mail.ru e-mail server. The message Subject and Body are in Russian, and the attached file is a Win32 EXE file (PE EXE file) with the "photo1.jpg.pif" name. The translated text appears as follows: Hello! Your address was given to me by a common friend of ours (the first address that came to his mind) I am a newcomer to the Internet and have just got this mailbox! So that this is the very first time I am writing an e-mail!!! He said that if I had any questions, I could ask youall I am pretty cute and sociable. (have a look at the photo) I'm waiting for a reply from you!!! Write me a bit about yourself and what you would like to know about me. Good bye! Good bye! :)))))))))
Sveta Kovaleva The worm also installs itself to the system and infects a few files in the system, as well as sends passwords and other confidential information out of the computer. To hide its activity, the worm displays a JPEG image of a girl. Infecting the system When the worm starts (being activated from an infected message), it installs itself to the system in several ways. First, the worm infects five files in the Windows directory: MPLAYER.EXE, WINHLP32.EXE, NOTEPAD.EXE, CONTROL.EXE, SCANREGW.EXE The worm infects them in a {companion:Comp} way: the original files are renamed with a .VXD extension, and then the worm copies itself instead of the original file with an .EXE extension. The worm then drops several of its copies - SCANREGW_EXE and LOADPE.COM - to the Windows system directory and IFNHLP.SYS to the Windows directory. The LOADPE.COM file is then registered in the auto-run Registry key: HKCRexefileshellopencommand = LOADPE.COM Later when any Win32 EXE file is started, this worm copy is activated, and infects an EXE file in the same companion manner. The SCANREGW.EXE file (this worm's copy) in the Windows system directory is then registered in the auto-run Registry key: HKLMSoftwareMicrosoftWindowsCurrentVersionRunServices ScanRegistry = %SystemDir%scanregw.exe Information that is sent out The worm sends out the following data from an infected computer (to its "master"): Remote access password and logins Local network logins and passwords BCSoft NetLaunch, PySoft AutoConnect and CureFtp information (if installed) Netscape, TheBat! system parameters (if installed) List of FAR ftp servers (if installed) FIDO TMail passwords (if installed) as well as system configuration and other information about the system The message containing this information has the following fields: From: Stat-generator v1.3 <%email_from%@mail.ru> To: <%email_to%@pisem.net> Subject: PLICT`01. Stat from %IP_address% Attach: STAT.PGP where: %IP_address% is the IP address of an infected machine. %email_from% is seven bytes long random string (for example, "syekqwc", "kryfmta", "nubipwd") %email_to% is seven bytes of a specially generated address that depend on the month and day number (for example, "pwdkryf", "rzhpxfn"). So the e-mail address to where the information is sent depends on the month number and current day.
Check other viruses! Be aware! Use Antiviral Software
Kavaklar.743
Description Kavaklar.743
It is a harmless memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM- and EXE-files that are executed. The virus contains the internal text string: Kavaklar v2.05 (c)Unterleutnant
Kazanir.768
Description Kazanir.768
It is a harmless memory resident parasitic virus. It hooks INT 21h and while executing any file the virus searches for .COM files, then writes itself to the end of the files that are found. The virus contains the text strings: Her zaman iyiler K A Z A N I R ! Dogruluktan A Y R I L M A ! *.com Version: DenemE ZEKVIR Virusu (c) 1 9 9 5 ASPARAGUS (tm) INTELLIGENT i.U iSLETME FAK.EXTERNAL - 3 0 4 AVCILAR/ i S T
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Bristol Airport Parking & Info Home Content Insurance Uk Starting A Franchise Business Anonymous Citizens Home Theater Design
|