VBS.Hard
Description VBS.Hard
This is an Internet-worm written in Visual Basic Script language (VBS). It spreads using MS Outlook Express. This worm spreads via e-mail by sending infected messages from infected computers. While spreading, the worm uses MS Outlook Express and sends itself to all addresses stored in the Windows Address Book. As a result, an infected computer sends as many messages to as many addresses kept in the Windows Address Book. It works only on computers on which the Windows Scripting Host (WSH) is installed. In Windows 98 and Windows 2000, WHS is installed by default. The worm arrives to a computer as an e-mail message with the attached file "www.symantec.com.vbs" that is the worm itself. The infected message in the original worm version contains: Subject = "FW: Symantec Anti-Virus Warning" Body = ----- Original Message ----- From: [warning@symantec.com] To: [supervisor@av.net]; [security@softtools.com]; [mark_fyston@storess.net]; [directorcut@ufp.com]; [pjeterov@goldenhit.org>; [kim_di_yung@freeland.ch]; [james.heart@macrosoft.com] Subject: FW: Symantec Anti-Virus Warning
Hello, There is a new worm on the Net. This worm is very fast-spreading and very dangerous!
Symantec has first noticed it on April 04, 2001.
The attached file is a description of the worm and how it replicates itself.
With regards, F. Jones Symantec senior developer Upon activation, the worm creates a fake Symantec virus information page about the non-existing virus "VBS.AmericanHistoryX_II@mm" and displays it. Then it creates several files that are used later for spreading. The first file is named "c:www.symantec_send.vbs" containing Visual Basic Script that instructs MS Outlook Express to send infected messages to all of the addresses in the Windows Address Book. The second file "c:message.vbs" contains Visual Basic Script that on November 24th, displays the following message: Some shocking news Don't look surprised! It is only a warning about your stupidity Take care! Both of these files are registered by the worm in the system registry in the autorun section. Thusly, these scripts gain control upon each Windows startup. The worm also registers a fake-virus information page as the start page of Internet Explorer. To avoid duplicate spreading from the same machine, the worm creates "HKLMSOFTWAREMicrosoftWABOE Done" in the system registry key and sets its value to "Hardhead_SatanikChild". In this way, it does not spread from the same machine twice.
Check other viruses! Be aware! Use Antiviral Software
IRC-Worm.ElSpy.2278
Description IRC-Worm.ElSpy.2278
This is an IRC worm that spreads through IRC channels using the mIRC client for spreading. The worm appears on a computer as the EL15_BMP.EXE DOS program. When this file is executed by a user, the worm installs itself into the system, and creates a temporary DOS batch helper that copies the worm file to the C:WindowsSystem directory and overwrites the mIRC SYSTEM.INI script file with new instructions. The commands that are written to SYSTEM.INI mIRC script intercept several events: when a new user enters the infected channel, (s)he is sent by the worm copy (the C:WINDOWSSYSTEMEL15_BMP.EXE file). on connection to a channel, the worm informs a user with a "EL15_SPY" nick about an infected client sends the IP address of an infected user the name of the IRC server the user is logged on to, and the port address. if the word "EL15" appears on the channel, the worm opens the C: drive on an infected computer as a file server (shares C: drive). on text "are_u" the worm sends the message: "EL15_send_kisses_to_U_:)__come_on!" followed with an IP address of an infected user. The worm contains the following text strings: Designed by Del_Armg0____26 Juin 1999____Keep It Load! MagicÇ%Software (c) 1999
IRC-Worm.Evion
Description IRC-Worm.Evion IRC-Worm.Evion Evion is an IRC worm spreading via IRC channels. The virus is written in Visual Basic Script (VBS). It overwrites .vbs and .html files on all local and mapped drives. Installing: When the worm is executed it does the following: Evion creates copies of itself in the root directory of disk C: in the file "Win32 Strt.exe.vbs " and in the system directory file "BootLoader.exe.vbs" as well as in the root Windows directory in the files"Jokes.htm" and "Winupdate.exe" Evion overwrites these existing files with a copies of itself:
%Windir%Readme.htm %Windir%Htmlhelp.htm %System%Winhelp32.exe %Mirc%script.ini
Evion registers the files "BootLoader.exe.vbs" and "Win32 Strt.EXE" in the automatic launch string of the system registry: HKEY_LOCAL_MACHINEMicrosoftWindowsCurrentVersionRun - (BootLoader.exe.vbs) HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunServices - (Win32 Strt.EXE)
Spreading Evion searches for the all .vbs files and overwrites the existing .vbs files with a copies of itself. Files that have the extensions .htm, .html, .asp, .htx, and .hta are replaced with the .HTML version of the worm. The "Script.ini" file is a short mIRC program that sends the %Windir%Jokes.htm file to everybody who enters an infected channel. Payload The worm activates its payload three different days (October 15th, November 23rd and December 25th), and displays a Message Box with the following respective texts:
with Message box title "my b-day" and text "happy birthday kefi" - 15 october with Message box title "11/23!" and text "holy sh*t! it's 11/23" - 23 november with Message box title "kefi [rRlf]" and text "Organized religion controls the world" - 25 december
On these payload activation days the worm also creates 16 text files in the Windows Startup folder. The file name uses the format: StartupEvion(n).txt, where n is between 0 and 15 (inclusive). These files contain 50 text strings of randomly generated text that is selected from these three lines:
You've done and gotten your self infected with Vbs.Evion by kefi [rRlf] [rRlf] ownz joo bitch Catfish_VX are lamers. This virus was constructed for them to steal
On days other than the ones on which the payload runs, a text document is created in the Desktop Windows directory. The file name uses the format "Desktop\%day% - %month%.vir.txt". These files contain the following text: today you did not experience the payload of Vbs.Evion sorry.. kefi [rRlf]
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Dell Inspiron 3700 Battery Ihr Handyvertrag Von Kotel.de Insert Tooling Map Of Ukraine Hotels Switzerland
|