|
|
I-Worm.Smile Viruses Information
| Name: |
I-Worm.Smile |
| Category: |
Viruses |
| Description:
|
Details
I-Worm.Smilex
This worm spreads via the Internet as an attachment to infected emails. It is written in Visual Basic and is a Windows PE EXE file, approximately 75KB in size.
Contains the text string:
Smile Internet Explorer CD_Open
Installation
When launched, the virus copies itself to C:WINDOWSStart MenuStartUpSmile.exe, ensuring that it will gain control every time Windows is started.
It also creates a copy of itself named Poems.exein the C: root directory.
It deletes the following files from the Windows directory:
Defrag.exe
Tuneup.exe
Regedit.exe
It also deletes C:Program FilesInternet ExplorerIexplorer.exe
It deletes all LNK files in C:WindowsDesktop.
It also deletes Norton Antivirus files and directories:
C:Program FilesSymantec Shared
C:Program FilesNorton AntiVirusv32scan.dll
C:Program FilesNorton AntiVirusNavtask.dll
C:Program FilesNorton AntiVirusNavtasks.dll
C:program filescommon filesSymantec Sharedscriptblocking
and copies itself under the names of the deleted files.
It also deletes Media Player:
C:Program FilesWindows Media Playerwmplayer.exe
Propagation via email
Every time the virus is launched, it sends itself to all addresses found in the MS Outlook address book.
Other
The worm creates an empty directory named OK on disk A: |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Macro.Word.Epidem.
Shine.64
Macro.Word.Malari
Joker0
I-Worm.Sober.
Joshi.
Tony.33
Pitch.59
Macro.Word.Macrokille
HLLC.Dope.487
|
|