IRC-Worm.Evion
Description IRC-Worm.Evion IRC-Worm.Evion Evion is an IRC worm spreading via IRC channels. The virus is written in Visual Basic Script (VBS). It overwrites .vbs and .html files on all local and mapped drives. Installing: When the worm is executed it does the following: Evion creates copies of itself in the root directory of disk C: in the file "Win32 Strt.exe.vbs " and in the system directory file "BootLoader.exe.vbs" as well as in the root Windows directory in the files"Jokes.htm" and "Winupdate.exe" Evion overwrites these existing files with a copies of itself:
%Windir%Readme.htm %Windir%Htmlhelp.htm %System%Winhelp32.exe %Mirc%script.ini
Evion registers the files "BootLoader.exe.vbs" and "Win32 Strt.EXE" in the automatic launch string of the system registry: HKEY_LOCAL_MACHINEMicrosoftWindowsCurrentVersionRun - (BootLoader.exe.vbs) HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunServices - (Win32 Strt.EXE)
Spreading Evion searches for the all .vbs files and overwrites the existing .vbs files with a copies of itself. Files that have the extensions .htm, .html, .asp, .htx, and .hta are replaced with the .HTML version of the worm. The "Script.ini" file is a short mIRC program that sends the %Windir%Jokes.htm file to everybody who enters an infected channel. Payload The worm activates its payload three different days (October 15th, November 23rd and December 25th), and displays a Message Box with the following respective texts:
with Message box title "my b-day" and text "happy birthday kefi" - 15 october with Message box title "11/23!" and text "holy sh*t! it's 11/23" - 23 november with Message box title "kefi [rRlf]" and text "Organized religion controls the world" - 25 december
On these payload activation days the worm also creates 16 text files in the Windows Startup folder. The file name uses the format: StartupEvion(n).txt, where n is between 0 and 15 (inclusive). These files contain 50 text strings of randomly generated text that is selected from these three lines:
You've done and gotten your self infected with Vbs.Evion by kefi [rRlf] [rRlf] ownz joo bitch Catfish_VX are lamers. This virus was constructed for them to steal
On days other than the ones on which the payload runs, a text document is created in the Desktop Windows directory. The file name uses the format "Desktop\%day% - %month%.vir.txt". These files contain the following text: today you did not experience the payload of Vbs.Evion sorry.. kefi [rRlf]
Check other viruses! Be aware! Use Antiviral Software
Macro.Excel.Queen
Description Macro.Excel.Queen
This virus infects Excel worksheets (XLS files). It comprises two macros in two modules: QUEEN, Auto_open. The virus does not manifest itself in any way. While infecting a system the virus creates the infected GLOBAL.XLM file in Excel startup directory. To infect other files the virus sets its infection macros QUEEN - this macros is executed on activation of any sheet.
Macro.Excel.Robocop
Description Macro.Excel.Robocop
This is an Excel macro virus. It contains two modules COP and ROBO. Module ROBO contains the auto-routine Auto_Open that is executed on opening an infected file. That macro infects the PERSONAL.XLS file and assigns virus code as being executed on activating a sheet (SheetActivate handler). As a result, the virus will infect current files (books) on activating a sheet. On March 1st the virus inserts the texts into current sheet: ROBOCOP Nightmare Joker [SLAM]
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Bygga Hus Economical News Kart News China Billigflüge T-shirts Bedrucken
|