Main Menu
Home
Bookmark
Contact Us



 
I-Worm.Energy. Viruses Information

Name: I-Worm.Energy.
Category: Viruses
Description: Details
I-Worm.Energy.a

This is an Internet worm spreading in attached RAR archives. The worm arrives to a computer as a SETUP.EXE file in an RAR archive that is attached to a message.
When the worm is started (executed from an infected RAR archive), it copies itself to the Windows system directory with the ENERGY.EXE name, registers itself as a system service and stays in the system memory. In the background, the worm then looks for processes that use the MAPI library (e-mail library), copies itself to these processed, and hooks the MAPISendMail function. When a message with an RAR file attached is sent, the worm opens the archived RAR, and copies itself there with the name SETUP.EXE. As a result, all RAR archives that are sent from an infected machine contain a SETUP.EXE file with the worm body in it.
The worm contains the text:
[I-Worm.Energy] by Benny/29A



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Macro.Word97.Ope
BAT.Batalia
DMR.120
Katya.73
Frodo.
Palm.Phag
Seagull.44
China.882.
Sibyll
K


 


© 2006-2008 spyware32.com - Privacy Policy