Virus Database


Solar.98

Description Solar.98

These are harmless memory resident parasitic viruses. They hook INT 21h Write (AH=40h) function and write themselves to the end of EXE files that are created, modified or copied. The viruses do not manifest themselves.

Check other viruses! Be aware! Use Antiviral Software

I-Worm.Calil

Description I-Worm.Calil

Calil is an Internet worm spreading via the Internet as an attachment to infected email messages.
The worm sends out messages with the following properties:

Subject: FW:FW: LILAC project video attach
Attachment name: LILAC_WHAT_A_WONDERFULNAME.avi
Attachment size: 12208 bytes
Message body: Things that the govt. dont want you to know

Installation
When the worm is launched on a computer for the first time, it tries to copy itself to the following hard coded locations:

c:win98 empLILAC_WHAT_A_WONDERFULNAME.avi c:windows empLILAC_WHAT_A_WONDERFULNAME.avi.exe c:win95 empLILAC_WHAT_A_WONDERFULNAME.avi.exe c:winnt empLILAC_WHAT_A_WONDERFULNAME.avi.exe c:winme empLILAC_WHAT_A_WONDERFULNAME.avi.exe c:winxp empLILAC_WHAT_A_WONDERFULNAME.avi.exe
Calil launches a copy of itself, automatically upon the restart of Windows by writing the following registry value:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun Lilac=(one of the paths specified above)
Next the worm shows a fake error message:
Windows Error54: Media Player not installed correctly

Replication
The worm gets e-mail addresses from the Windows and Outlook address books, and sends infected messages to these addresses. It uses Outlook to send infected messages. Other
Calil changes the system registered owner information by writing the following registry values:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersion RegisteredOwner=xEnOcrAtEs LegalNoticeCaption=Owned by: LegalNoticeText=Owned by: xEnOcrAtEs
This forces Windows to show the following message when starting:
Owned by: xEnOcrAtEs

I-Worm.Calposa

Description I-Worm.Calposa
Calposa is a worm virus spreading via the Internet as an attachment to infected emails as well as through the Kazaa file sharing network. The worm itself is a Windows PE EXE file about 57KB in length and is written in Visual Basic.
The infected email messages have the following attributes:
Subject: Anti-Virus Programs are corrupting your Software!

Body:
Want to know why you get junk mail? Well Here is proof that AV's are corrupting your programs and Sell your Private information to Web Company's! Why do you think there are so much virus's out there? well its these Company's that spread them and then sell you there product to delete them! check it out nowall (p.s. its attatched)
Attach: ActiveX.exe, or Telnet.exe, or MSWord.exe
The worm activates from an infected email only when a user clicks on the attached file. The worm then installs itself to the system and runs its spreading routine and payload.
Installing
While installing the worm copies itself to the system under the following names:
C:WindowsActiveX.exe
C:WindowsSCR.exe
C:WindowsExplorer.exe
C:WindowsTelnet.exe
C:WindowsMSWord.exe
C:WindowsFUCK_AVs.exe
C:Windows egedit.exe
C:WindowsMixer.exe
C:WINDOWSSystemExplorer.exe

The worm does not register any of these files neither in system registry auto-run key, nor in any else "auto-run" key or command.
Spreading: Email
To send infected messages the worm uses MS Outlook and sends messages to all addresses found in Outlook address book.
Spreading: Kazaa
The worm copies itself to the "C:Program FilesKaZaaMy Shared Folder" directory with following names:
norton_crack.exe
UT3_full_crack.exe
Windows_Hack.exe
Sims_Patch.exe

If this directory is a Kazaa file-sharing directory, the worm will spread over the Kazaa network.
Payload
The worm displays the message:
UH OH WORM!
... Calposa by Industry @ ANVXgroup ...

The worm writes to the "c:WindowsSystem.ini" file following data:
[About]
Author = Industry
VXgroup = ANVXgroup (Auxnet)
Virus = ANVX (WIN32.calposa@mm)
Shouts to = Indovirus, mANiAC89, Retro, Iwing, and every one else.
Fuck = Fuck all AV's, we keep you in a job so give us a bit of slack!
To the rest = ANVX the one and only!

On April 1st the worm deletes all files in following directories:
C:Windows C:WindowsSystem32 C:WindowsSystem C:Windowsinf C:Program FilesKazaa
then it deletes the file:
C:AutoExec.bat

and displays the message:
Industry ...ping? pong!...
On February 16th the worm displays a red colored picture with a text "ANVX by industry" on it.
On April 2nd the worm displays the message:
UH OH WORM! ... Second Release From Industry ...

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com