I-Worm.Vote
Description I-Worm.Vote
This Internet worm spreads via e-mail messages using MS Outlook. Upon being executed, the worm sends infected messages to all addresses stored in the Outlook address book, then it overwrites all HTML files on the local disk drives. Upon the next Windows start-up, the worm tries to delete all files in the Windows folder, and reboots the computer. The worm arrives to a computer as an e-mail message with an attached executable file that is the worm itself. The malicious message contains the following:
The worm doesn't run automatically from e-mail. It is activated only when a user starts it manually (by double-clicking on the attachment). Upon being executed, the worm sends infected messages to all addresses stored in the Outlook address book. Then it opens two Internet browsers utilizing sites that are closed at the moment. Also, it replaces the Internet Explorer start-up page with one of its own. Following this, the worm drops two different VBS files. The first one is named "MixDaLaL.vbs" that the worm creates and runs immediately in the Windows folder. This file has a script program that searches for files with HTM and HTML extensions on all removable and local hard drives, and overwrites them with a short text: AmeRiCa allFew Days WiLL Show You What We Can Do !!! It's Our Turn >>> ZaCkEr is So Sorry For You The second VSB file the worm drops into the Windows system folder with the name, "ZaCker.vbs", and registers it in the auto-run registry section. This means the file will be automatically executed upon the next Windows start-up. Upon being executed, it attempts to delete all files in the Windows directory, overwrites AUTOEXEC.BAT with a command destroying all data on drive C:, and then it displays the following message:
The worm finally reboots the computer. As a result, the system may be rendered unbootable or all data may be destroyed.
Check other viruses! Be aware! Use Antiviral Software
Assassin_II.959
Description Assassin_II.959
It is a dangerous memory resident parasitic stealth virus. It intercepts two functions of INT 21h (CloseFile and ReadHandle) and writes itself at the beginning of COM- and EXE-files that are closed. The original beginning of the file is saved out of file body by the manner of the "Beast" virus. On reading from the file the virus substitutes the infected file with its original form. The virus uses several complex tricks. On installation it does not hook INT 21h, but modifies the not documented DOS tables to pass the control to the virus body on file closing and on reading from the file. That can cause the system to crash. While infecting the file, the virus uses not documented System File Table and INT 2Fh calls. The virus contains the internal text string: This is [Assassin] written by Dark Slayer in Keelung. Taiwan <R.O.C>
Assignation Family
Description Assignation Family
These are not dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of EXE files that are executed. While installing into the memory the "Assignation.653" virus sets the system date to February 5th. Other viruses do not manifest themselves. The viruses contain the text strings: "Assignation.426,436": 386 Virus - by Qark/VLAD - 1996
"Assignation.653": kraD evoL Helloall. This is Assignation Virus V1.00...^_^ Today You will have a Date for Someone:-) May Be with you friend,Brother,or Dark Lover:-) Copy Allright By Dark Lover ^_^ 04/22/1996 in Kaohsiung,Taiwan,R.O.C
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
J.m.d StÄdservice Lundabygdens Djursjukhus Aktiebolag WahlstrÖms Optik Aktiebolag Nets I GÄvle Ab Hyttings Damfrisering
|