
I-Worm/Klez.H
heavily reported - Apr 20,
2002
Klez.H
is a modified variant of original Klez.E
worm
and it is rapidly spreading in the wild. I-worm/Klez.H
arrives as an e-mail attachment with
different names. The attachments are
embedded within the e-mail and it won't
visible to the user|
More
details
I-Worm/APost
reported in the wild - Sept
03, 2001
APost
is an Internet worm uses Microsoft Outlook to
spread. The worm is 24,576
bytes
long and written in Visual Basic 6.0. It
needs "MSVBVM60.dll" to spread
otherwise it will show dll missing error.
The attachment name will be
"Readme.exe". It is also known
as I-Worm.Readme or W32.Apost@mm |
More
details
CodeRed
Worm strikes unprotected IIS servers
- Jul 20, 2001
CodeRed worm
spreads using .ida buffer overflow attack
vulnerability in IIS Web servers. The
worm will attack unprotected IIS servers.
Web administrators are requested to
install the security patch provided by
Microsoft. | More
details
I-Worm/SirCam
- New deadly worm spreading
- Jul 19, 2001
SirCam
is a mass mailing worm spread using
e-mail addresses stored in Windows
Address book and also collects addresses
from temporary Internet folder. It will
e-mail the infected files using its own
SMTP engine. SirCam is also network aware
worm. It searches for network shares and
infects them too. |
More
details
VBS/HomePage
- A new worm spreads rapidly
- May 08, 2001
VBS/HomePage aka
VBS/VBSWG.X is a encrypted VB script worm
uses Microsoft outlook to spread. The
email message subject will be " Homepage " and the
attachment will be "homepage.HTML.vbs"
and the message body will be "Hi!
You've got to see this page! It's really
cool ;O)".
| More
details
I-Worm/BadTrans
reported in the wild - April
11, 2001
BadTrans
is an encrypted worm spreads via MAPI
function of Microsoft Outlook and it also
drops Trojan.PSW.Hooker.b in the victims
PC. The virus author can steal username
and password details using the password
stealer. | More
details
Win32/Magistr
- A high risk worm spreading
- Mar 04, 2001
Win32/Magistr
is a complex polymorphic worm spreads via
email and it contains virus components to
infect PE files [*.EXE,
*.SCR] in
Windows environment. It infects local
machine and PCs connected to the local
network (LAN). It is discovered in March
2001 and frequently reported in the wild.
| More
details
Win32/Kriz
to strike again on Christmas day
- Dec 20, 2000
Win32/Kriz is a
PE file virus infects EXE files under
Win9x and WinNT 4.0 platforms. This virus
will wake up or get activated on 25th of
December [Christmas day] and it will
damage the motherboard and the hard disk.
The damage caused could be extreme and
expensive. | More
details
Hybris
aka Hahaha Worm Spreading Rapidly
- Nov 14, 2001
Hybris
is a complex deadly worm, it will update
the plugins from the virus author's site
or through a virus conference news group
alt.comp.virus. The worm uses Win95/Babylonia
virus
technique to download plugins, but it
uses strong encryption on plugins using
RSA 128 bit keys. The worm patches
WSOCK32.DLL to email automatically.
| More
details
I-Worm/Prolin
reported in the wild - Dec
4, 2000
Proilin
is an Internet worm, uses Microsoft
Outlook to email itself.The worm is Prolin
36,834
bytes long and written in Visual Basic
version 6. It needs
"MSVBVM60.dll" to spread
otherwise it show DLL missing error. The
e-mail attachment name will be will
"Creative.exe".
| More
details
I-Worm/MTX
- A virus carrier spreads via e-mail
- Sep 26, 2000
MTX
is a complex encrypted worm spreads via
email and carries a virus to infect local
machine files. It is discovered one month
back and frequently reported in the wild.
When
executed, the worm patches
WSOCK32.DLL to email automatically. The
virus component uses EPO ( Entry
Point Obscuring ) technology
to infect files. | More
details
Are
you forced to wish "SHANKAR'S"
birthday - Jul 23, 2000
W97M/Marker-O is
a modified variant of W97M/Marker virus.
It is a Polymorphic Word macro virus.
While opening the document, If checks for
system date. If the month is 7 and day is
greater than or equal to 23 it will
display the message "Did You
Wish Shankar on his Birthday ?".
It will alow the user to proceed. |
More
details
VBS/Stages
worm downs many e-mail servers
- Jun 21, 2000
VBS/Stages is a
multi application Windows worm uses
Microsoft outlook, mIRC, Pirch and mapped
drives to spread. Because of the mass
mailing routine it downs many e-mail
servers. The attachment name will be
"LIFE_STAGES.TXT.SHS" and
size will be 39,936 bytes. |
More
details
VBS/Plan
- A new love letter style mass mailer
detected - Jun 10, 2000
VBS/Plan is a new
modified variant of VBS/LoveLetter worm uses
Microsoft outlook to spread. Also it
needs Windows Scripting Host to infect
the system. While opening the
e-mail attachment, will copy LINUX32.vbs
and a random file name in windows system
folder and reload.vbs in windows folder. Then it changes
the registry
settings so that the the script is
automatically executed when the system is
restarted.| More
details
W97M/Resume
- A mass mailer with deadly payload
- May 27, 2000
Resume
is a word macro worm makes use of the
MAPI functions in Microsoft Outlook to
retrieve the current user profile and
password for server logon. This Virus
grabs e-mail addresses from the address
book of Microsoft Outlook and resends the
mail. It is very similar to Melissa
virus. It won't infect any document in
the system but will deletes files in the
mapped dirves.| More
details
VBS/NewLove
worm with deadly payload -
May 19, 2000
VBS/NewLove is a
modified variant of VBS/Love Letter worm
uses Microsoft outlook to spread. It
contains a very dangerous payload and it
will overwrite all files (including
windows system files) with virus code in
a fly. The damaged files cannot
be recovered. |
More
details
I-Worm/SouthPark
- reported in the wild - May
12, 2000
South
Park is an Internet worm, uses Microsoft
Outlook and other different techniques
like copying "South Park.exe"
to floppy drives and Mapped drives to
spread. The worm is 19,968 bytes long and
written in Visual Basic. It needs
"MSVBVM50.dll" to spread
otherwise it will show dll missing error.
The e-mail attachment name will be
"South Park.exe".|
More
details
VBS/LoveLetter
spreads at lightening speed
- May 4, 2000
VBS/LoveLetter is
a VB Script uses Microsoft outlook and
Mirc clients to spread. It is spreading
faster than Melissa virus. It causes
heavy e-mail traffic and downs many mail
servers. There are several variants
reported in the wild. The attachments
will be LOVE-LETTER-FOR-YOU.TXT.VBS,
mothersday.vbs, Urgent_virus_warning.vbs,
IMPORTANT.TXT.VBS,
Virus-Protection-Informations.vbs,
ArabAir.TXT.vbs, BEWERBUNG.TXT.vbs,
KillEmAll.TXT.vbs, protect.vbs or
Very Funny.vbs . |
More
details
Wscript/Kak
worm reported in the wild -
March 24, 2000
Wscript/Kak is a
worm that exploits security
vulnerabilities in Microsoft Internet
Explorer and Microsoft Outlook in a way
similar to Bubbleboy
worm.
It will ONLY infect PCs running Windows
98 with Internet Explorer 5
and Outlook or Outlook Express.
| More
details
I-Worm/Plage
reported in the wild -
February 6, 2000
Plage
is an e-mail worm, uses MAPI functions to
infect e-mail messages. The worm is
102400 bytes long written in Borland C++.
The worm has an icon similar to PKLITE
self extracting program, very similar to
Win32/ExploreZip worm. The infection
method is also similar to ExploreZip worm
but it won't delete the data files in the
system. | More
details
Win95/Babylonia
virus detected - December
11, 1999
W95/Babylonia
is a polymorphic virus, When executed,
the virus infects .EXE and .HLP files.
When it detects an Internet connection,
it attempts to connect to a Web site
hosted by a virus authoring group, and if
successful, it downloads additional
components of the complete virus to the
host PC. | More
details
Dangerous
E-mail worm Minizip -
December 6, 1999
MiniZip
is a
compressed variant of the original
ExploreZip worm,
it uses standard e-mail software such as
Outlook, Outlook Express and Exchange to
spread. It infects Windows 95/98/NT
systems and damages the data. It searches
for the files with extensions doc, xls,
ppt, h, asm, c, cpp in the local hard
drives and mapped drives and reduces the
file size to zero byte. | More
details
W97M/Prilissa
- A new variant of Melissa -
September 20, 1999
W97M/Prilissa
virus is a new variant of Melissa virus
infects Word 97 Documents. Prilissa
virus makes use of the MAPI functions in
Microsoft Outlook to retrieve the current
user profile and password for server
logon. This Virus grabs the first 50
addresses from the address book of
Microsoft Outlook and resends the mail.
It will format your harddisk on Christmas
day. | More
details
Win32/FunLove
virus Detected - November
16, 1999
This
virus is a Win32 PE file virus infects
EXE, SCR, OCX files under Win9x and WinNT
4.0 platforms. The infected files will
increase by 4099 bytes. What is notable
about this virus is that it uses a new
strategy to attack the Windows NT file
security system and it runs as a service
on Windows NT systems. |
More
details
E-mail
worm VBS/Bubbleboy Detected
- November 10, 1999
VBS/Bubbleboy is
the first e-mail worm to infect computers
without using attachments. Historically,
as long as you don't open e-mail
attachments you're safe from virus
infection, but this changes all that.
It will
ONLY infect PCs running Windows 98
with Internet Explorer 5 and Outlook
or Outlook Express. |
More
details
New
E-mail worm VBS/Monopoly Detected
- August 8, 1999
Monopoly is a
VBScript worm, uses Microsoft OUTLOOK and
it sends information about who runs the
file. When run, it will display a message
saying "Bill Gates is guilty of
monopoly. Here is the proof.". Then
it will show a JPG file, which shows Bill
Gates face in the Monopoly game.|
More
details
Security
hole detected in MS-Office -
July 30, 1999
A vulnerability
in an MS Office 97 driver makes it
possible for users to become infected by
a virus or trojan simply by opening an
e-mail message or visiting a Web page.
This security hole is possible because of
an ODBC problem with the Jet 3.51 driver
(located in ODBCJT32.DLL) shipped with MS
Office 97. | More details
Beware
of Back Orifice 2000 Trojan
- June 27, 1999
BO2K
is a hacker agent, it allows the computer
to be remotely controlled by another
user. It was created by the Cult of Dead
Cow hackers group in July 1999. It works
on Windows 95, 98 and Windows NT
platforms.| More
details
Dangerous
E-mail worm Explorezip -
June 22, 1999
ExploreZip
is an e-mail worm, it uses standard
e-mail software such as Outlook, Outlook
Express and Exchange to spread. It
infects Windows 95/98/NT systems and
damages the data. It searches for the
files with extensions doc, xls, ppt, h,
asm, c, cpp in the local hard drives and
mapped drives and reduces the file size
to zero byte. It will infect other
networked computers too. | More
details
Spy
Tool - Netbus trojan detected
- June 12, 1999
NetBus is a
remote administration tool, just like the
famous Back Orifice tool. However, Netbus
works on Windows 95/98/NT. Netbus is
basically a small utility for remote
controlling of one computer from
different computer using the Network. But
it is being more misused as a Trojan than
an actual tool.|
More
details
Beware
of X97M/PAPA Virus - April
3, 1999
Papa
virus is a Microsoft Excel virus which
also spreads through email. When an
infected Excel spreadsheet is opened, the
Papa virus makes use of the MAPI
functions in Microsoft Outlook to
retrieve the current user profile and
password for server logon. The virus will
then access the Outlook client address
book and select up to 60 recipients to
automatically send new email messages.| More
details
Pronet
warns new OUTLOOK Virus W97M/Melissa
- March 27, 1999
Melissa
virus makes use of the MAPI functions in
Microsoft Outlook to retrieve the current
user profile and password for server
logon. This Virus grabs the first 50
addresses from the address book of
Microsoft Outlook Express and resends the
mail .The infected word document contains
the porno site address. It infects Word97
and Office 2000 documents.| More
details
New
type of E-mail worm Happy99 detected
- March 7, 1999
The
is a Win32-based e-mail and newsgroup
worm. It displays fireworks when executed
first time as Happy99.exe. When executed
first time, it creates SKA.EXE and
SKA.DLL in the system directory. Also it
modifies WSOCK32.DLL to infect.| More
details
CIH -
The first virus attacks BIOS chips
- August 14, 1998
A more dangerous
and deadly virus called "CIH"
has spread rapidly and remains dormant in
many computers. This virus will wake up
or get activated on 26th of April and it
will damage the motherboard and the hard
disk. The damage caused could be extreme
and expensive.|
More
details

|