Virus Database


Trojan.BAT.VSX

Description Trojan.BAT.VSX

This primitive Trojan is written in BAT and is 1471 bytes in size.
It creates a directory named VSX\Infected in the C:\ root directory. It then moves files with the extensions .BAT, .VBS, .DLL, .SYS, .OCX, and .MOD from the C:\ root directory to this directory.
After moving the files, the virus displays the following message:
This version of Virii ScanÏ X has detected that you have infected files in 'C:\' drive(s).
All infected file have been placed in C:\VSX\Infected.
Would you like to have Virii ScanÏ X delete the file(s) for you?

Y) Yes
N) No
If the user presses N, the following message will be displayed
'Thank You for using Virii Scano X for your computer protection.'.
and exists to the system.
If the user presses Y, the Trojan will cause the message below to be displayed:
You have chosen to have Virii ScanÏ X to delete your infected file(s).
Are you sure you wish to continue?
Y) Yes
N) No
If the user chooses N, the program exits. If the user presses Y, then the directory VSX\Infected\ will be deleted.
The Trojan then displays the following message:
All infected files have been deleted.
Thank you for using Virii Scano X for your computer protection.

Would you like to view the ReadMe file?

Y) Yes
N) No
If the user presses Y, the system time will be set to 11.11.11.

Check other viruses! Be aware! Use Antiviral Software

I-Worm.MyLife.e

Description I-Worm.MyLife.e

MyLife is a family of worms (different versions) spreading through the Internet as infected email attachments. The worms themselves are Windows PE EXE files, written in Visual Basic and compressed by the UPX file compression utility.
The worm is activated only if users click on the attachment. Once executed, MyLife installs itself into the system and runs its spreading routine.
When MyLife is launched for the first time it shows either a window with a picture or message, which one depends on the particular version.
Two possible MyLife pictures:


While installing this worm copies itself to the Windows System directory and registers this copy (file) in the system registry auto-run key.
MyLife uses Microsoft Outlook to send messages to all addresses found in the Microsoft Outlook Address Book.
File size : about 12Kb.
Decompressed file size : about 39Kb.
Email content:
Subject:
sexxxyyy Screen Saver
Body:

Hiii
How are youu!!?
look to the New Screen Saver it's vvvery verrrry ffffunny :-) :-)
i promise you will love it? Ok
buyyyy
========No Viruse Found======== MCAFEE.COM

Attached file name:
Screen.scr
File name in the infected system:
%SystemDir%Screen.scr
Affected registry key:

HKCUSoftwareMicrosoftWindowsCurrentVersionRun
Screen=%SystemDir%Screen.scr
Visual effect: when MyLife is launched for the first time it displays the following message:

? Error ?
? Error 1452544 File Not Found ?
While installing itself into the system, MyLife sends a notification e-mail message to the address zarx200@email.com - the contents of which are:
Subject:
New Screen Saver

Body:
New Never Hood buy
Payload: when MyLife is launched for the second time it deletes all the files in the root directories of disks C:, D:, E:, F:, G: as well as in the C:My Documents directory, files with extensions .SYS, .EXE, .INI in the Windows directory and files with the extensions .VXD, .SYS in the Windows System directory.

I-Worm.MyLife.f

Description I-Worm.MyLife.f

MyLife is a family of worms (different versions) spreading through the Internet as infected email attachments. The worms themselves are Windows PE EXE files, written in Visual Basic and compressed by the UPX file compression utility.
The worm is activated only if users click on the attachment. Once executed, MyLife installs itself into the system and runs its spreading routine.
When MyLife is launched for the first time it shows either a window with a picture or message, which one depends on the particular version.
Two possible MyLife pictures:


While installing this worm copies itself to the Windows System directory and registers this copy (file) in the system registry auto-run key.
MyLife uses Microsoft Outlook to send messages to all addresses found in the Microsoft Outlook Address Book.
File size : about 8Kb.
Decompressed file size : about 25Kb.
Email content:
Subject:
sexxxyyy Screen Saver
Body:
Hiiiii
How are youuuuuuuu?
look to the notepad it's vvvery verrrry ffffunny :-) :-)
i promise you will love it :-)
Notepad = list
list = 37
buyyyy
========No Viruse Found========
MCAFEE.COM
--------------------------------------------------------

Attachment name:
List480.TXT.scr
File name in the infected system:
%SystemDir%List480.TXT.scr
Affected registry key:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
sys=%SystemDir%List480.TXT.scr
Visual effect: when the worm is launched for the first time it displays the following message:

Payload: MyLife checks the current date, if the current minute value is greater or equal to 50, it executes format commands for disks D:, E:, F:, G:, H:, I: and also deletes all the files and directories on disk C: Following these actions the worm shows the following message:

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Web Hosting Servers
Asus Motherboards
Lifestyle
Free Blog
Ne Car Loans

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com