|
|
I-Worm.FriendMes Viruses Information
| Name: |
I-Worm.FriendMes |
| Category: |
Viruses |
| Description:
|
Details
I-Worm.FriendMess
This dangerous Internet worm is written in Visual Basic Script language. For spreading, the worm uses MS Outlook 98/2000. If another mailer is used, the worm is not able to spread, but runs its payload routine (see below).
The worm arrives to a computer as an e-mail message:
Subject: FRIEND MESSAGE
Body: A real friend send this message to you.
The message has an attached "FRIEND_MESSAGE.TXT.vbs" file. Depending upon system settings, a real extension of the attached file (".vbs") may not be shown. In this case, the filename of an attached file is displayed as a "FRIEND_MESSAGE.TXT".
The attached file contains script written in Visual Basic Script language. Upon being activated by double clicking on an attached file, the script gains control and the worm begins work.
The worm creates the file "FRIEND_MESSAGE.TXT.vbs" in the Windows system directory, and writes its own code there (this file is used later by a worm for spreading its copies). Then the worm displays the following message:
If you receive this message remember forever: A precious friend
in all the world like only you! So think that!
After this, the worm runs its spreading routine. This routine gains access to MS Outlook and sends infected messages to all recipients from the Outlook address book. These messages look the same as the arrived one (see above). While spreading, the worm stores infected-recipient addresses in the system registry and does not send messages to already-infected recipients.
The worm contains a payload routine that overwrites a "C:AUTOEXEC.BAT" file with commands that delete all files in the Windows directory, Windows system directory and Windows temporary directory. These commands in the "C:AUTOEXEC.BAT" file are executed upon system start-up. |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Dos.184.
Topa.247
Macro.Word.HaH
GreenMonster.71
TotalChaos.
LosLobos.53
Nuke.Awake.600.
TrojanSpy.Win32.KI
Morse.106
Advent.Syslock.355
|
|