IRC-Worm.Kromber
Description IRC-Worm.Kromber
This worm Trojan spreads via IRC channels, and is 3584 bytes in size. Propagation When launching, the worm checks for an active IRC client on the victim machine. If it finds this, the worm will send a link to a remote site to all accessible IRC channels by using the /amsg command: http://www.kromberg.at/[censored]/show.php?f=drunkchicks.jpg LOL It also attempts to install this link as the name of a channel and comments to it. If another user clicks on this link, the remote site will be contacted. This site contains a malcious VBS script (which will be detected by Kaspersky Anti-Virus as TrojanDropper.VBS.Inor.h). This will install and launch the worm's executable file, named browsercheck.exe on the victim machine.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Mercy
Description Macro.Word.Mercy
This is the encrypted Word macro virus. It contains six macros in documents: Autoexec, AutoOpen and four macros with random names. The infected NORMAL.DOT contains eight macros: AutoClose, ToolsMacro, FileTemplates, Organizer and four macros with random selected names. The virus infects the global macros area (NORMAL.DOT) on opening an infected document (AutoOpen) and writes itself to documents that are closed (AutoClose). The names of random named macros the virus saves in document's variables (in case of infected document) or in the WIN.INI file in the [Intl] section in strings Here_1, Here_2, e.t.c (in case of NORMAL.DOT). The virus detects itself in the system by the string "I_am_Here" in the [Intl] section. On 11th of any month the virus displays the MessageBox: Episode 2: TenFaces [the series continueall] The 10Faces is back! hey AVers the name is 10Faces!! not Mercy.A -(c)reator of NoMercy-
The virus contains the commented text: Hiya Pyro are you decrypt again ! I don't borrow the code from "Outlaw" anymore (it's now original) this random code is smaller than before and better randomize result Using Simple-Little-Fast -random generator Thankz to ya Pyro without your critics this never happen
Macro.Word.Messa
Description Macro.Word.Messa
This is an encrypted macro virus. It contains 21 macros: CUS, EOP, ESA, NIZ, PLT, WEV, CROM, CUST, ESAA, INFO, MESSA, WATCH, BEEPER, README, AutoExec, AutoOpen, FileOpen, FileSave, FileSaveAs, TheVWarning, POO. The virus infects the system on opening an infected document - it copies this document with new name THEVWARN.ING to Word Startup-Path and User-Dot-Path. As a result the virus will activate each time Word will start (Word reads and loads templates from Startup-Path and User-Dot-Path). The virus also infects the global macro area. The documents get infection on opening and closing. Depending on the current time the virus hooks timer and sets on timer the BEEPER macro. It also runs the OOP macro (it is renamed POO) that on pressing Alt-Ctrl-Shift-K is runs the TheVWarning macro. TheVWarning macro in one minute runs the WATCH macro. The WATCH macro renames the macros: OEX - AutoExec OOP1 - AutoOpen EOP - FileOpen ESA - FileSave ESAA - FileSaveAs NIZ - Organizer CROM - ToolsMacro PLT - FileTemplates CUS - ToolsCustomize CUST - ToolsCustomizeToolbar WEV - ViewToolbars
The BEEPER macro beeps and displays the MessageBox: I am so sorry. I do not mine it to disturb You. But maybe all there is something that You have to do! <Time> THE 'V' WARNING <Date>
The MESSA macry displays the message: THE 'V' WARNING MESSAGE Sorry to interrupt You. I think You are tired, because You have worked until midnight. so I suggest You to go to bed now and tomorrow You could work harder than this day. Kota Pelajar, Yogyakarta.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|