Win95.Yobe
Description Win95.Yobe
This is a dangerous memory resident parasitic Windows virus. It uses system calls that are valid under Win95/98 only, and can't spread under NT. The virus also has bugs and often halts the system when run. Despite this, the virus has very unusual way of spreading, and it is interesting enough from a technical point of view. The virus can be found only in two files: "SETUP.EXE" on floppy disks and "SETUP .EXE" in the root of the C: drive (there is one space between the file name and ".EXE" extension). On floppy disks, the virus uses a trick to hide its copy. It writes its complete code to the last disk sectors and modifies the SETUP.EXE file to read and execute this code. The infected SETUP.EXE file looks just as a 512-byte DOS EXE program, but it is not. While infecting this file, the virus uses a DirII virus method: by direct disk sectors read/write calls, the virus gets access to disk directory sectors, modifies the "first file cluster" field and makes necessary changes in disk FAT tables. As a result, the original SETUP.EXE code is not modified, but the directory enters points to the virus code instead of the original file clusters. When the infected SETUP.EXE is run from the infected floppy disk, this DOS component of the virus takes control, reads the complete virus body from the last sectors on the floppy disk, then creates the "C:SETUP .EXE" file, writes these data (complete virus code) to there and executes. The virus installation routine takes control then, installs the virus into the system and disinfects the SETUP.EXE file on the floppy drive. While installing itself into the system, the virus creates a new key in the system registry to activate itself upon each Windows restart: HKLMSoftwareMicrosoftWindowsCurrentVersionRun YOBE=""C:SETUP .EXE" YOBE"
The virus then switches to the Windows kernel level (Ring0), allocates a block of system memory, copies itself to there and hooks disk-file access Windows functions (IFS API). This hook intercepts file opening calls, and upon opening the SETUP.EXE file on the A: drive, the virus infects it. The virus has additional routines. First, one of them looks for "AVP Monitor" and "Amon Antivirus Monitor" windows and closes them; the second one, depending on the random counter, displays a line with the words "YOBE" to the left side of the screen.
Check other viruses! Be aware! Use Antiviral Software
I-Worm.Rastam
Description I-Worm.Rastam
This is Internet worm spreading with emails by affecting Eudora email client. The infected message arrives with the text "Help us go back to home!" at the end of the message body and attached DOS COM file "www.back2afrika.com" (the virus tries to cheat an user by disguising its .COM extension with URL-like name). If user activates the attached COM file, the worm gets control, creates EXE file with random name in temporary directory, and runs it. That EXE file is PE EXE file and contains main worm routine which registers worm text and attachment as Eudora auto-signature. As a result all outgoing mails will have worm text and attached COM file (see above) pasted to the end of the message. The worm code contains the text strings: RASTAMAN SOFTWARECLIENTSMAILEUDORASHELLOPENCOMMAND EUDORA.INI Use Signature Settings Help us go back to home! begin 644 www.back2afrika.com Haile Selassie is Jesus Christ! (tehporp sih si anceV dnA) Last string is "And Vecna is his prophet" written backwards. The known worm version has a bug and can't spread.
I-Worm.Redesi
Description I-Worm.Redesi
This is an Internet worm, which spreads via e-mail messages using Microsoft Outlook. When launched, the worm copies itself to the following locations: C:Si.exe C:ReDe.exe c:Disk.exe c:Common.exe c:UserConf.exe
Then, it sends itself to all recipients of victim's Outlook Address book. If Microsoft Outlook is not present at victim's computer, the worm is unable to spread. The subject of messages sent by the worm is selected randomly from a list of pre-defined strings. The attached file is always one of the following: Si.exe Common.exe UserConf.exe ReDe.exe Disk.exe
Resedi.a
If the worm was launched on the computer for the first time, it show a message: Title: Microsoft Windows Update Message: Your Windows Update has been successful. If current date is 11 November 2001, and Windows short date format is either mm/dd/yy, or dd/mm/yy, the worm writes several command to autoexec.bat, so in Windows 9x the C: drive will be formatted after reboot. The worm writes the following registry key to start automatically with Windows: HKLMSoftwareMicrosoftWindowsCurrentVersionRunRede The worm sends itself in e-mail messages that have the following content: Subject is one of the following: FW: Microsoft security update. FW: Security Update by Microsoft. FW: IT departments on state of HIGH ALERT. FW: Important news from Microsoft. FW: Stop terrorists computer viruses reign. FW: Terrorists release computer virus. FW: Emergency response from Microsoft Corp. FW: Terrorist Emergency. Latest virus can wipe disk in minutes. FW: Microsoft Update. Final Release Candidate. FW: New computer virus.
Message body: Just recieved this in my email I have contacted Microsoft and they say it's real !
-----Original Message----- From: Microsoft Support Desk [mailto:Support@microsoft.com] Sent: 17 October 2001 15:21 Subject: Security Update
Due to the recent spate of email spread computer viruses Microsoft Corp has released a security patch. Please apply the attached file to your Windows computer to stop any futher spread or these malicious programs. Regards Microsoft Support The worm's body contains the following strings: Mind the Threefold Law ye should, three times bad and three times good. When misfortune is enow, wear the blue star on thy brow. True in love ye must ever be, lest thy love be false to thee. These words the Wiccan Rede fulfill: An ye harm none, do what ye will. Rede(c)Si 2001 all heh, want my phone number too ?!? Sick of all thes 3rd world gits spreading worms. Time for a bit of Welsh stuff :)
Resedi.b The subject of the messages sent by the worm is one of the following: Kev Gives great orgasms to ladeez!! -- Kev hell is coming for u, u will be sucked into a bottomless pit!!! -- Gaz Scientists have found traces of the HIV virus in cows milk...here is the proof -- Will Yay. I caught a fish -- Six I don't want to write anything but Si is bullying me. -- Jim I want to live in a wooden house -- Arwel Michelle still owes me £10 ... shit ! -- Si Why have I only got cheese and onion crisps? I hate them !! -- Si A new type of Lager / Weed variant...... sorted ! My dad not caring about my exam results -- by Michelle
Message body: heh. I tell ya this is nuts ! You gotta check it out !
When messages are sent, the worm shows the following message: Title: %file path%\%filename% is not a valid Win32 application. Message: %file path%\%filename% is not a valid Win32 application.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Unblock Facebook Dj Muenchen Windows 7 Forum Florida Keys Travel Elfrisken
|