Virus Database


Macro.Word.Meldung

Description Macro.Word.Meldung

This virus contains three macros:
Documents NORMAL.DOT
A1 DateiSpeichernUnter
AutoOpen AO1
B1 AutoExec

The virus infects the global macros area on opening an infected document (AutoOpen) and infects documents on saving them with new names (DateiSpeichernUnter - FileSaveAs).
On the 17th of any month the virus displays the MessageBox:
Meldung!
Dark Tremor Virus Copyright 1998 by Dark Tremor

Check other viruses! Be aware! Use Antiviral Software

I-Worm.MyLife.a

Description I-Worm.MyLife.a

I-worm MyLife is the worm virus currently spreading through the Internet in the form of an attachment to infected e-mails. The worm itself is a Windows PE EXE file about 30 Kb in size, written in Visual Basic and is a compressed file. It is compressed by UPX - its decompressed size is about 55Kb.
Infected messages have the following properties:
Body Text:
Hiiiii
How are youuuuuuuu?
look to the digital picture it's my love
vvvery verrrry ffffunny :-)
my life = my car
my car = my house
The worm is attached to infected e-mail messages within the attachment named "My Life.scr".

The worm is activated from infected e-mails when a user clicks on the attachment My Life.scr.
Once clicked upon the worm installs itself into the system and runs its spreading routine.
When the worm is launched for the first time it shows a window with a picture. Once this window is closed the worm runs its payload.
Installing
While installing itself the worm copies itself to the Windows System directory with the name "My Life.scr" and registers this file in the system registry auto-run key:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun stmgr=%SYSTEM%My Life.scr
Where %SYSTEM% is the Windows System directory.
Spreading
The worm uses Microsoft Outlook to send out infected e-mail messages to all addresses found in the Microsoft Outlook Address Book.
Payload
The worm checks the current date, if the current minute value is more than 45 it executes the following payload routine. The worm deletes files with extensions .SYS and .COM in the root directory of disk C:, files with extensions .COM, .SYS, .INI, .EXE in the Windows directory and files with extensions .SYS, .VXD, .EXE, .DLL in the Windows System directory.

I-Worm.MyLife.b

Description I-Worm.MyLife.b

The Internet worm MyLife.b is a worm virus being spread via the Internet as an e-mail attachment. The worm itself is a Windows PE EXE file about 11Kb in length, written in Visual Basic. It is compressed by UPX, its decompressed size is about 32Kb.
The infected e-mail messages have the following properties:
Subject:
bill caricature
Body:
Hiiiii
How are youuuuuuuu?
look to bill caricature it's vvvery verrrry ffffunny :-) :-)
i promise you will love it? ok
buy ========No Viruse Found======== MCAFEE.COM --------------------------------------------------------
Attachment:
CARI.SCR
Screen shot of infected MyLife.b e-mail:

The worm activates from an infected e-mail only when a user clicks on the attached file. The worm then installs itself into the system and runs its spreading routine.
When the worm is launched for the first time it shows a window with a picture.

Installing
While installing the worm copies itself to the Windows system directory with the name "cari.scr" and registers this file in the system registry auto-run key:

HKCUSoftwareMicrosoftWindowsCurrentVersionRun win=%SYSTEM%cari.scr
%SYSTEM% is the Windows System directory.
Spreading
To send infected messages the worm uses Microsoft Outlook, it sends messages to all addresses found in the Microsoft Outlook Address Book. The worm also gets victim e-mail addresses from MSN Messenger e-mail base.
Payload
Once installed in the system (after Windows reboot following infection) the worm checks the current date, if the current hour value is 8, the worm executes its payload routine, deleting the following files:

c:*.*
d:*.*
e:*.*
f:*.*
Also deleted are: *.sys files in the Windows directory and *.vxd, *.sys, *.ocx, and *.nls files in the Windows system directory.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



A-bygg & Mark I Mellansverige Ab
Liljeholm Konsult Aktiebolag
Edwards Transport .m C Och Taxi Service
Alltema I LinkÖping Ab
BiltjÄnst I Hudiksvall Aktiebolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com