Virus Database


Milena.1160.a

Description Milena.1160.a

It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. It contains the text string:
LOVE I Love Milenaall

Check other viruses! Be aware! Use Antiviral Software

I-Worm.Mydoom.g

Description I-Worm.Mydoom.g

This worm spreads via the Internet as an attachment to infected messages. The worm itself is a Windows PE EXE file of 32256 bytes, packed using UPX.
The worm will be launched only if the user opens the archive and executes the infected file. The worm will then install itself to the system and start propagating.
The worm includes a backdoor function, and is also coded to conduct a DoS attack on www.symantec.com and symantec.com
Once the file has been unpacked, the following text string is visible:
to netsky's creator(s): imho, skynet is a decentralized peer-to-peer neural network. we have seen P2P in Slapper in Sinit only. they may be called skynets, but not your shitty app.
Installation
Once the worm is launched, it may open Windows Notepad, which will display a random selection of characters.
When installing, the worm copies itself under a random name, with the extension .exe or .scr to the Windows system directory. It registers this file in the system registry to ensure that the worm is launched each time Windows is started:
[HKLMSoftwareMicrosoftWindowsCurrentVersionRun]
[HKCUSoftwareMicrosoftWindowsCurrentVersionRun]
"<random characters>"="%System%<name of file>"
The worm creates a file with a random name and a .dll extension in the Windows system directory. This is the backdoor component. This file is also registered in the system registry:
[HKCRCLSID{E6FB5E20-DE35-11CF-9C87-00AA005127ED}InProcServer32]
"<random characters>"="%System%<name of file.dll>"
This ensures that the DLL is launched as an Explorer.exe child process.
To flag its presence in the system, the worm creates a mutex <name of computer>theta,. This ensures that only one copy of the worm can be launched at once.
The worm copies itself to all accessible hard disks under a random name; it also creates copies of itself in ZIP archives.
It searches all accessible hard drives for files with the extensions listed below. It then creates copies of itself under these file names, adding either an .exe or a .pif extension.
avi
doc
jpg
mp3
mp4
wav
wma
xls
Mass mailing
The mass mailing function is similar to the other versions of Mydoom, with a few insignificant differences.
Remote administration
The worm opens TCP ports 80 and 1080 to receive commands. The backdoor component can act as a proxy server, and also download and launch files.
Other
The worm is coded to detect and terminate the following processes in memory:

adaware.exe
alevir.exe
arr.exe
au.exe
avpupd
avwupd
backweb.exe
bargains.exe
beagle
belt.exe
blss.exe
bootconf.exe
bpc.exe
brasil.exe
bundle.exe
bvt.exe
cfd.exe
click
cmd32.exe
cmesys.exe
d3du
datemanager.exe
dcomx.exe
divx.exe
dllcache.exe
dllreg.exe
dpps2.exe
dssagent.exe
emsw.exe
explore.exe
fsg_4104.exe
fuck
gator.exe
gmt.exe
hbinst.exe
hbsrv.exe
hotactio
hotfix.exe
hotpatch.exe
htpatch.exe
hxdl.exe
hxiul.exe



idle.exe
iedll.exe
iedriver.exe
iexplorer.exe
inetlnfo.exe
infus.exe
infwin.exe
init.exe
intdel.exe
intren
isass.exe
istsvc.exe
jdbgmrg.exe
kazza.exe
keenvalue.exe
kernel32.exe
launcher.exe
lnetinfo.exe
loader.exe
mapisvc32.exe
md.exe
mfin32.exe
mmod.exe
mostat.exe
msapp.exe
msbb.exe
msblast.exe
mscache.exe
msccn32.exe
mscman.exe
msdm.exe
msdos.exe
msiexec16.exe
mslaugh.exe
msmgt.exe
msmsgri32.exe
msrexe.exe
mssys.exe
msvxd.exe
netd32.exe
nssys32.exe
nstask32.exe



nsupdate.exe
onsrvr.exe
optimize.exe
patch.exe
penis
pgmonitr.exe
porn
powerscan.exe
prizesurfer.exe
prmt.exe
prmvr.exe
pussy
ray.exe
rb32.exe
rcsync.exe
reged
run32dll.exe
rundll.exe
rundll16.exe
ruxdll32.exe
sahagent.exe
save.exe
savenow.exe
sc.exe
scam32.exe
scrsvr.exe
scvhost.exe
service.exe
servlce.exe
servlces.exe
showbehind.exe
sms.exe
smss32.exe
soap.exe
sperm
spoler.exe
spoolcv.exe
spoolsv32.exe
srng.exe
ssgrate.exe
start.exe
stcloader.exe



support.exe
svc.exe
svchostc.exe
svchosts.exe
svshost.exe
system.exe
system32.exe
sysupd.exe
taskmg
taskmo
teekids.exe
trickler.exe
tsadbot.exe
tvmd.exe
tvtmd.exe
updat
upgrad
utpost.
webdav.exe
win32.exe
win32us.exe
winactive.exe
win-bugsfix.exe
window.exe
windows.exe
wininetd.exe
wininit.exe
wininitx.exe
winlogin.exe
winmain.exe
winnet.exe
winppr32.exe
winservn.exe
winssk32.exe
winstart.exe
winstart001.exe
wintsk32.exe
winupdate.exe
wkufind
wnad.exe
wupdater.exe
wupdt.exe




DoS attacks
The worm searches the victim machine for the file C:Feedlist. If it detects this file, it will attempt to conduct a DoS attack on www.symantec.com and symantec.com by sending looped multiple GET requests.

I-Worm.Mydoom.m

Description I-Worm.Mydoom.m

I-Worm.Mydoom.m spreads via the Internet as an attachment to infected messages.
The worm itself is a Windows PE EXE file approximately 27KB in size, packed using UPX. The unpacked file is approximately 50KB in size.
The worm is only activated when a user opens the archive and launches the infected file by double-clicking on it. The worm will then install itself on the system and begin propagating.
The worm contains a backdoor function.
Part of the body of the worm is encrypted.
Installation
When installing, the worm copies itself as 'java.exe' to the Windows root directory, and registers this file in the system registry. This ensures the worm will be launched each time the infected system is booted.
[HKLMSoftwareMicrosoftWindowsCurrentVersionRun]
[HKCUSoftwareMicrosoftWindowsCurrentVersionRun]
JavaVM = %windir%java.exe
This ensures the worm will be launched each time the infected system is booted.
The worm also creates a file named 'services.exe.', which is 8192 bytes in size, in the Windows root directory. This file is an additional component, and is also added to the system registry:
[HKLMSoftwareMicrosoftWindowsCurrentVersionRun]
[HKCUSoftwareMicrosoftWindowsCurrentVersionRun]
Services = %windir%services.exe
Mailing messages
The worm searches the victim machine for email addresses to harvest, and then sends itself to these addresses by directly connecting to the recipient's SMTP server.
It also harvests addresses by using the following search engines:
Google
Lycos
Altavista
Yahoo
Infected messages
Sender's address: (either chosen from the list below or spoofed):
MAILER-DAEMON
Mail Administrator
Automatic Email Delivery Software
Post Office
The Post Office
Bounced mail
Returned mail
Mail Delivery Subsystem
Message header (chosen at random from the list below):
Message could not be delivered
hello
Hi
error
status
test
report
delivery failed
Message could not be delivered
Mail System Error - Returned Mail
Delivery reports about your e-mail
Returned mail: see transcript for details
Returned mail: Data format error
{{The|Your} m|M}essage could not be delivered
instruction
Message body (chosen at random from the list below)
The message body will be altered to correspond to the user's details.
Dear user {$t|of $T},{ {{M|m}ail {system|server} administrator|administration} of $T would like to {inform you{ that{:|,}|}|let you know {that|the following}{.|:|,}}|||||}
{We have {detected|found|received reports} that y|Y}our {e{-|}mail |}account {has been|was} used to send a {large|huge} amount of {{unsolicited{ commercial|}|junk} e{-|}mail|spam}{ messages|} during { this|the {last|recent}} week.
{We suspect that|Probably,|Most likely|Obviously,} your computer {had been|was} {compromised|infected{ by a recent v{iru}s|}} and now {run|contain}s a {trojan{ed|}|hidden} proxy server.
{Please|We recommend {that you|you to}} follow {our |the |}instruction{s|} {in the {attachment|attached {text |}file} |}in order to keep your computer safe.
{{Virtually|Sincerely} yours|Best {wishe|regard}s|Have a nice day}, {$T {user |technical |}support team.|The $T {support |}team.}
{The|This|Your} message was{ undeliverable| not delivered} due to the following reason{(s)|}:
Your message {was not|could not be} delivered because the destination {computer|server} was {not |un}reachable within the allowed queue period. The amount of time a message is queued before it is returned depends on local configuration parameters.
Most likely there is a network problem that prevented delivery, but it is also possible that the computer is turned off, or does not have a mail system running right now.
Your message {was not|could not be} delivered within $D days: {{{Mail s|S}erver}|Host} $i is not responding.
The following recipients {did|could} not receive this message: <$t>
Please reply to postmaster@{$F|$T} if you feel this message to be in error. The original message was received at $w{ | }from {$F [$i]|{$i|[$i]}}
----- The following addresses had permanent fatal errors ----- {<$t>|$t}
{----- Transcript of {the ||}session follows ----- all while talking to {host |{mail |}server ||||}{$T.|$i}: {>>> MAIL F{rom|ROM}:$f <<< 50$d {$f... |}{Refused|{Access d|D}enied|{User|Domain|Address} {unknown|blacklisted}}|554 <$t>..
. {Mail quota exceeded|Message is too large} 554 <$t>... Service unavailable|550 5.1.2 <$t>... Host unknown (Name server: host not found)|554 {5. 0.0 |}Service unavailable; [$i] blocked using {relays.osirusoft.com|bl.spamcop.net}{, reason: Blocked|} Session aborted{, reason: lost connection|}|>>> RCPT To:<$t> <<< 550 {MAILBOX NOT FOUND|5.1.1 <$t>... {User unknown|Invalid recipient|Not known here}}|>>> DATA {<<< 400-aturner; %MAIL-E-OPENOUT, error opening !AS as output|}{<<< 400-aturner; -RMS-E-CRE, ACP file create failed|}{<<< 400-aturner; -SYSTEM-F-EXDISKQUOTA, disk quota exceeded|}<<< 400}|} The original message was included as attachment {{The|Your} m|M}essage could not be delivered
Attachment name:
The attachment name is generated at random.
Attachment extension (chosen at random from the list below):
cmd
bat
com
pif
scr
doc
exe
The worm may also be sent in the form of a ZIP archive.
Other
The worm opens TCP port 1034 in order to receive remote commands.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Funny Jokes
Holzterrasse
Av Cart With Wheels
Prohaus
Directory

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com