Virus Database


Bash.3241

Description Bash.3241

These are dangerous memory resident polymorphic parasitic viruses. They hook INT 21h and write themselves to the end of COM and EXE files that are executed or opened. The viruses also affect ARJ archives and insert an infected dropper file into them. The viruses use many anti-debugging tricks, which are buggy, and often halt the system because of that.
The viruses perform several actions directed to disable anti-viruses. First of all, while installing memory resident, they look for TBAV anti-virus driver in the memory, and disable it. They also looks for anti-virus data files, and delete them:
ANTI-VIR.DAT CRC.SVS MSAV.CHK BOOT.MS
ANTIVIR.DAT CRC_.SVS SMARTCHK.CPS BOOT.NTZ
ANYCHECK.VAL FILES.VVL TBUTIL.DAT BOOT.TAV
AVP.CRC FINGERP.VVF ZZ##.IM IV.INI
CHKLIST.CPS IM.PRM _ADINF.INI PART.NTZ
CHKLIST.MS IVB.INI AV.CRC VIRSORT.DAT
CHKLIST.TAV IVB.NTZ BOOT.CPS TBUTIL.DAT

The viruses also patch the AVP 2.x package, if it is installed. They creates the BIZATCH.AVB database in the AVP directory, and register it in the AVP.SET file. See "Anti-AVP" for more details.
From September 17th till October the viruses attampt to erase disk sectors and displays a picture, but fails because of a bug. The picture looks like follows:
all. NO! ... ... MNO! ...
..... MNO!! ...................... MNNOO! ...
..... MMNO! ......................... MNNOO!! .
.... MNOONNOO! MMMMMMMMMMPPPOII! MNNO!!!! .
... !O! NNO! MMMMMMMMMMMMMPPPOOOII!! NO! ....
...... ! MMMMMMMMMMMMMPPPPOOOOIII! ! ...
........ MMMMMMMMMMMMPPPPPOOOOOOII!! .....
........ MMMMMOOOOOOPPPPPPPPOOOOMII! ...
....... MMMMM.. OPPMMP .,OMI! ....
...... MMMM:: o.,OPMP,.o ::I!! ...
.... NNM:::.,,OOPM!P,.::::!! ....
.. MMNNNNNOOOOPMO!!IIPPO!!O! ..... ,
... MMMMMNNNNOO:!!:!!IPPPPOO! .... ***** ================-
.. MMMMMNNOOMMNNIIIPPPOO!! ...... AuRoDrEpH.....
...... MMMONNMMNNNIIIOO!.......... The Drow
....... MN MOMMMNNNIIIIIO! OO .......... Was Back !!!
......... MNO! IiiiiiiiiiiiI OOOO ...........
...... NNN.MNO! . O!!!!!!!!!O . OONO NO! ........
.... MNNNNNO! ...OOOOOOOOOOO . MMNNON!........
...... MNNNNO! .. PPPPPPPPP .. MMNON!........
...... OO! ................. ON! .......

The viruses also deletes disk files. In the root directories of all available logical drives they delete the "?????x??.*" files, where "x" is drive's letter. They also look for the SYSTEMIOSUBSYSHSFLOP.PDR file in the Windows directory, and delete it.
The viruses contain the text strings:
CARO: Please label this creation Hare.Little_Brother :-) or if you
want BSHME.Buggy.7xxx - This version is for educational purpose only!
Greetx to all virus writers! Still buggy but it works...
-=[ 1996 ]=-
-=[ U$A ]=-
-=[ BSHME ]=-

Check other viruses! Be aware! Use Antiviral Software

I-Worm.Scooter

Description I-Worm.Scooter

This is an Internet worm spreading in infected e-mails and sending its copies to IRC channels. The worm itself is a Windows executable file about 200K in length written in Microsoft Visual C++. It was discovered in the wild in September 2000 in compressed form about 170K in length (compressed by PECompact utility).
The worm is related to the "Scrambler" Internet worm.
When an infected file is executed, the worm creates its copy in the Windows system directory. That file has a random 5-letter name, for example: BJEFG.EXE, FBHGE.EXE. That file will be used later to send worm copies to Internet and IRC channels.
To spread to IRC channels, the worm infects mIRC client by creating (overwriting) a SCRIPT.INI file in standard mIRC directories on all drives from C: through F: the affected file names appear as the following:
mircscript.ini
PROGRA~1mircscript.ini
The worm writes a short script there that sends its copy to each user that enters the infected channel.
To send infected e-mail messages, the worm creates the SCOOTER.VBS VisualBasic script program in the Windows system directory and writes there a script program that connects MS Outlook and sends e-mail messages to first 90 users from the MS Outlook address book. The messages have an infected attachment (worm copy) and the subject is:
Faster.. harder.. your PC will run like a scooter!
The message body is empty. The worm then spawns this script, and spreads to the Internet as a result.
To prevent duplicate sending, the worm creates the SCOOTER.SYS file in the Windows system directory and writes the text there:
Faster.. harder.. scooter!'
If such a file exists (with any data inside), the worm skips sending infected e-mails.
To disguise its activity, the worm extracts from its body the SCOOTER.MP3 music file and opens it.

I-Worm.Scorpion

Description I-Worm.Scorpion

This is a dangerous worm that spreads via the Internet in infected e-mails. The worm itself is a Windows application written in Delphi and about 370K in size.
Upon being executed (by clicking on the attached file, for instance), it installs itself into the system, registers itself as a service process (hidden application), then sends infected messages (with its attached copy), and, depending on the system date, runs its payload routine.
Installation to System
The worm copies itself to the Windows system directory with a name randomly selected from the following variants:
Play.exe
Bigs as.exe
Zorro.exe
Honey.exe
Jefes.exe
Corte de pelo.exe
Tangas.exe
Canibal.exe
Picadita.exe
Josefina.exe
and registers that file in the Registry auto-run key:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun Scorpion=%filename%
E-mail Spreading
The worm sends itself from infected machines as an attached file with random names as above, and with the Subject and message Body randomly selected from the following variants:
Subjects:
Sorpresa !!!
Este si que es un buen presente
Diviertanse
Todo debe estar limpio
Echale un ojo a esto
Buena PECHOnalidad
Con todo mi aprecio
El aguijon de Scorpion
Traseros
Mujeres
Message body:
Abrelo sin miedo que, no es ningun Virus
No tiene ningun Virus
Abrelo no hay PELIGRO, esta limpio de Virus
Mira que bueno esta esto
Espero que esto te guste
Scorpion hace de las suyas
Esto si esta interesante abrelo que no hay peligro
Dime si te gusto
No tiene Virus, asi que abranlo y disfrutenlo
Observa el gran poder de las mujeres en su parte trasera
To send infected messages, the worm connects to a SMTP server. The worm obtains the name of the SMTP server from the default-system settings.
A victim's e-mail addresses are obtained from the WAB file (Windows Address Book). The messages also are sent each time to:
jajachistes@topica.com
tavojaja@yahoogroups.com
cartones@egroups.com
pensamientos@egroups.com
huateque@egroups.com
jacastro@geoline.net
forodelphi2000@yahoo.com.ar
The worm sends e-mails immediately upon the first start-up, then in time intervals, depending on its internal time counters.
Payloads and other
The worm finds and deletes all *.INF and *.SYS files on a drive where Windows is installed, and the system is destroyed due to this in most cases.
Starting in September, and the 15th of each month, the virus runs itself with some video effect.
The worm also creates and modifies the following registry keys:
HKEY_LOCAL_MACHINESoftwareScorpionHelp
Mail = Negro
Fack = Rojo
These keys indicate that: 1st key - e-mail messages have already been sent; 2nd key - INI and SYS files have been deleted.
Depending on its internal time counters, the worm also closes all active application windows, opens/closes the CD drive, blinks the Num/Caps/Scroll-lock keys, an displays 500 messages:
Scorpion ya está aquí !!!!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Upload Multiple Images
Appetizers
Snitter
Cdon.com
Infidelity In Marriage

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com