|
|
I-Worm.MyLife. Viruses Information
| Name: |
I-Worm.MyLife. |
| Category: |
Viruses |
| Description:
|
Details
I-Worm.MyLife.f
MyLife is a family of worms (different versions) spreading through the Internet as infected email attachments. The worms themselves are Windows PE EXE files, written in Visual Basic and compressed by the UPX file compression utility.
The worm is activated only if users click on the attachment. Once executed, MyLife installs itself into the system and runs its spreading routine.
When MyLife is launched for the first time it shows either a window with a picture or message, which one depends on the particular version.
Two possible MyLife pictures:
While installing this worm copies itself to the Windows System directory and registers this copy (file) in the system registry auto-run key.
MyLife uses Microsoft Outlook to send messages to all addresses found in the Microsoft Outlook Address Book.
File size : about 8Kb.
Decompressed file size : about 25Kb.
Email content:
Subject:
sexxxyyy Screen Saver
Body:
Hiiiii
How are youuuuuuuu?
look to the notepad it's vvvery verrrry ffffunny :-) :-)
i promise you will love it :-)
Notepad = list
list = 37
buyyyy
========No Viruse Found========
MCAFEE.COM
--------------------------------------------------------
Attachment name:
List480.TXT.scr
File name in the infected system:
%SystemDir%List480.TXT.scr
Affected registry key:
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
sys=%SystemDir%List480.TXT.scr
Visual effect: when the worm is launched for the first time it displays the following message:
Payload: MyLife checks the current date, if the current minute value is greater or equal to 50, it executes format commands for disks D:, E:, F:, G:, H:, I: and also deletes all the files and directories on disk C: Following these actions the worm shows the following message: |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
TotalTrash.216
Search.512.
Salamanca.120
Este.30
Infector.82
Guinness.82
WhiteNoise.485
Win32.Niko.517
3E.38
Lamento.269
|
|