|
|
I-Worm.MyLife. Viruses Information
| Name: |
I-Worm.MyLife. |
| Category: |
Viruses |
| Description:
|
Details
I-Worm.MyLife.a
I-worm MyLife is the worm virus currently spreading through the Internet in the form of an attachment to infected e-mails. The worm itself is a Windows PE EXE file about 30 Kb in size, written in Visual Basic and is a compressed file. It is compressed by UPX - its decompressed size is about 55Kb.
Infected messages have the following properties:
Body Text:
Hiiiii
How are youuuuuuuu?
look to the digital picture it's my love
vvvery verrrry ffffunny :-)
my life = my car
my car = my house
The worm is attached to infected e-mail messages within the attachment named "My Life.scr".
The worm is activated from infected e-mails when a user clicks on the attachment My Life.scr.
Once clicked upon the worm installs itself into the system and runs its spreading routine.
When the worm is launched for the first time it shows a window with a picture. Once this window is closed the worm runs its payload.
Installing
While installing itself the worm copies itself to the Windows System directory with the name "My Life.scr" and registers this file in the system registry auto-run key:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun stmgr=%SYSTEM%My Life.scr
Where %SYSTEM% is the Windows System directory.
Spreading
The worm uses Microsoft Outlook to send out infected e-mail messages to all addresses found in the Microsoft Outlook Address Book.
Payload
The worm checks the current date, if the current minute value is more than 45 it executes the following payload routine. The worm deletes files with extensions .SYS and .COM in the root directory of disk C:, files with extensions .COM, .SYS, .INI, .EXE in the Windows directory and files with extensions .SYS, .VXD, .EXE, .DLL in the Windows System directory. |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
BAT.Sakur
Brackets.136
Cernoch.106
Berserker.353
Calu.242
I-Worm.PrettyPar
Rasputi
Ming Famil
Paraguay.275
Pizelun.359
|
|