Macro.Word97.Groovie
Description Macro.Word97.Groovie
This virus contains twenty macros in one module "Groovie": ID_Status, Install_Status, The_Groovie_Core, DocCodeCore, NormCodeCore, OrbitCoreCode, Groovie_Run, AutoOpen, AutoClose, AutoExit, FileSaveAs, filesave, fileclose, fileprint, IP_Love_You, mscript, viewvbcode, ToolsMacro, FileTemplates, Check_For_Doc. The virus infects the system or documents when auto-macro is activated. It infects the system not only by infecting the NORMAL.DOT file, but also by creating the infected DATA.DOT file in the Word Startup directory. The DATA.DOT file contains module named ORBIT. While infecting the virus uses VBA export/import functions and save/read virus code to/from temporary C:GROOVIE.SYS file. The virus deletes the menus "Tools/Macro" and "Tools/Templates and add-insall". On entering the ViewVBCode menu the virus displays the MessageBox: ò ALT-F11 ò says... It's GROOVIE
It also sets the "groovie" label on the C: drive. On Windows NT depending on the random number the virus tries to create machine IP configuration to the C:IP.TXT file and sends it to FTP server of FRISK International anti-virus company (F-PROT).
Check other viruses! Be aware! Use Antiviral Software
I-Worm.Klez.e
Description I-Worm.Klez.e
Installation The worm copies itself to the Windows system directory with a random name that starts from "Wink", i.e., "Winkad.exe". Infection The worm searches several registry keys for links to applications: SoftwareMicrosoftWindowsCurrentVersionApp Paths Then the worm tries to infect EXE applications that it finds. When infecting an EXE, the worm creates a file with the same name and random extension and also hidden+system+readonly attributes. This file is used by the worm to run the original infected program. When the infected file is run, the worm extracts the original file to a temp file with the original filename plus 'MP8' and runs it. The worm infects RAR archives by copying itself to archives with a randomly generated name. The name of the infected file is selected from the following list: setup install demo snoopy picacu kitty play rock and has either one or two extensions, where the last one is ".exe", ".scr", ".pif" or ".bat". Replication: e-mail The subject of the infected message is either selected from the following list or is generated randomly: Hi, Hello, Re: Fw: how are you let's be friends darling don't drink too much your password honey some questions please try again welcome to my hometown the Garden of Eden introduction on ADSL meeting notice questionnaire congratulations sos! japanese girl VS playboy look,my beautiful girl friend eager to see you spice girls' vocal concert Japanese lass' sexy pictures The worm can also generate the subject of the message from the following strings: Undeliverable mail--%% Returned mail--%% a %% %% game a %% %% tool a %% %% website a %% %% patch %% removal tools Where %% is selected from the following list: new funny nice humour excite good powful WinXP IE 6.0 W32.Elkern W32.Klez The body of the infected messages is either blank, or has randomly generated contents. The worm constructs the following variants for Subject and Message body: Subject: A %1 %2 Body: This is a %1 %2 %3 or %4 where %1, %2 and %3 are randomly (depending on content) selected from variants: special WinXP game new IE 6.0 website funny W32.Elkern tool nice W32.Klez patch humour W32.Klez.E removal tools excite good powful %3 are lines: This game is my first work. You're the first player.
I wish you would enjoy it. I hope you would enjoy it. I expect you would enjoy it. %4 contains strings such as these: %5 give you the %1 removal tools %1 is a dangerous virus that spread through email. %1 is a very dangerous virus that can infect on Win98/Me/2000/XP. For more information,please visit http://www.%5.com where %5 is selected from the variants: Symantec, Mcafee, F-Secure, Sophos, Trendmicro, Kaspersky The result may look as follows: A special new game This is a new game This game is my first work. You're the first player. I wish you would enjoy it.
A very funny website This is a funny website I hope you would enjoy it.
A very powful tool Hello,This is a powful tool I hope you would enjoy it.
A IE 6.0 patch Hello,This is a IE 6.0 patch I hope you would enjoy it.
W32.Elkern removal tools Kaspersky give you the very W32.Elkern removal tools W32.Elkern is a very dangerous virus that can infect on Win98/Me/2000/XP. For more information,please visit http://www.Kaspersky.com
W32.Klez.E removal tools W32.Klez.E is a dangerous virus that spread through email. Kaspersky give you the W32.Klez.E removal tools For more information,please visit http://www.Kaspersky.com Attached file: a Win32 PE EXE file with a random name, which has either an ".exe" extension or a double extension. The worm uses an IFrame security breach to launch automatically when an infected message is viewed. Payload On the 6th of odd months, the worm executes a payload routine that fills all available files on a victim's computer in local and network disks with random content. These files can't be recovered and must be restored from a backup copy. Other Klez.e randomly and depending on different conditions attaches randomly selected files from the local disk to emails. Therefore the email message has two attached files: 1. a copy of the worm and 2. an additional file. The worm looks for following file extensions for attachments: .txt .htm .html .wab .doc .xls .jpg .cpp .c .pas .mpg .mpeg .bak .mp3 As a result, the worm is able to send personal or confidential information from the computer, disclosing it. The worm scans for the active processes that contain the following strings, and terminates them: Sircam Nimda CodeRed WQKMM3878 GRIEF3878 Fun Loving Criminal Norton Mcafee Antivir Avconsol F-STOPW F-Secure Sophos virus AVP Monitor AVP Updates InoculateIT PC-cillin Symantec Trend Micro F-PROT NOD32
I-Worm.Klez.h
Description I-Worm.Klez.h
The Klez.h variant of the Klez worm family is very similar to Klez.e. The differences are: This variant has no payload and doesn't destroy files. It brings with it additional variants of infected Messages, Subjects and Bodies. Example of a Klez.h email message Subject and Body content: Worm Klez.E immunity Klez.E is the most common world-wide spreading worm. It's very dangerous by corrupting your files. Because of its very smart stealth and anti-anti-virus technic, most common AV software can't detect or clean it. We developed this free immunity tool to defeat the malicious virus. You only need to run this tool once,and then Klez will never come into your PC. NOTE: Because this tool acts as a fake Klez to fool the real worm, some AV monitor maybe cry when you run it. If so,Ignore the warning,and select 'continue'. If you have any question,please mail to me. This worm looks for files with the following extensions: .txt .htm .html .wab .asp .doc .rtf .xls .jpg .cpp .c .pas .mpg .mpeg .bak .mp3 .pdf Depending on several conditions Klez.h attaches a file with one of the above listed extensions to infected emails (as the second attached file). As a result, confidential or personal information may be sent out and made public. Another example of Klez.h email message content: Win32 Klez V2.01 & Win32 Foroux V1.0 Copyright 2002,made in Asia About Klez V2.01: 1,Main mission is to release the new baby PE virus,Win32 Foroux 2,No significant change.No bug fixed.No any payload. About Win32 Foroux (plz keep the name,thanx) 1,Full compatible Win32 PE virus on Win9X/2K/NT/XP 2,With very interesting feature.Check it! 3,No any payload.No any optimization 4,Not bug free,because of a hurry work.No more than three weeks from having such idea to accomplishing coding and testing How do I delete the Klez virus? 1) disconnect the infected PC from the local network (if exists) 2) run clrav.com file If the program says "nothing to clean" - run it from the command line with the paramrter /scanfiles, for example: C:clrav.com /scanfiles 3) re-boot your PC in Safe Mode 4) run clrav.com again 5) reinstall the anti-virus package and update the anti-virus database 6) run Kaspersky AV Scanner and check all the hard drives
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Waagen Algarve Car Hire Portugal Digital Delivery Script Concrete Staining Austin Prohaus.com
|