Main Menu
Home
Bookmark
Contact Us



 
I-Worm.Vot Viruses Information

Name: I-Worm.Vot
Category: Viruses
Description: Details
I-Worm.Vote

This Internet worm spreads via e-mail messages using MS Outlook. Upon being executed, the worm sends infected messages to all addresses stored in the Outlook address book, then it overwrites all HTML files on the local disk drives. Upon the next Windows start-up, the worm tries to delete all files in the Windows folder, and reboots the computer.
The worm arrives to a computer as an e-mail message with an attached executable file that is the worm itself. The malicious message contains the following:

The worm doesn't run automatically from e-mail. It is activated only when a user starts it manually (by double-clicking on the attachment).
Upon being executed, the worm sends infected messages to all addresses stored in the Outlook address book. Then it opens two Internet browsers utilizing sites that are closed at the moment. Also, it replaces the Internet Explorer start-up page with one of its own. Following this, the worm drops two different VBS files.
The first one is named "MixDaLaL.vbs" that the worm creates and runs immediately in the Windows folder. This file has a script program that searches for files with HTM and HTML extensions on all removable and local hard drives, and overwrites them with a short text:
AmeRiCa allFew Days WiLL Show You What We Can Do !!! It's Our Turn >>> ZaCkEr is So Sorry For You
The second VSB file the worm drops into the Windows system folder with the name, "ZaCker.vbs", and registers it in the auto-run registry section. This means the file will be automatically executed upon the next Windows start-up. Upon being executed, it attempts to delete all files in the Windows directory, overwrites AUTOEXEC.BAT with a command destroying all data on drive C:, and then it displays the following message:

The worm finally reboots the computer. As a result, the system may be rendered unbootable or all data may be destroyed.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Intruder Famil
Variol
Tiso.94
Macro.Word97.Redte
BadBoy.Lubec.113
BachKhoa.442
Penza Famil
Macro.Word.Jakuts
Macro.Word97.Bench.
HMA_Boot.


 


© 2006-2008 spyware32.com - Privacy Policy