English
Deutsch
Home
Vireninfos
VBS/Guorm
Suche
Home
Support
Lösungen
Produkte
Downloads
Vireninfos
Statistiken
VDF Historie
Virenkunde
Datei-Upload
Sicherheits-News
In-the-Wild-Viren
Unternehmen
Presse
Partner
Newsletter
VBS/Guorm - VBS script virus
Siehe auch
Kurzfassung
Vollständig
Statistik
Wie würden Sie diese Information bewerten?
Wertlos
Hervorragend
Alias:
VBS/Gorum.a
Type:
Worm
Size:
~
Origin:
Date:
05-31-2000
Damage:
Sent by email.
VDF Version:
6.20.00.00
Danger:
Medium
Distribution:
Medium
Distribution
The worm sends itself to all addresses found in Outlook. If Outlook 2000 is installed, the virus sends the following email:
Subject:
You know what it is. ;-P
Body:
Check it out!
Attachment name- formed out of the following text strings:
links
cool
funny
anti-loveletter
guorm
pot
win2k
icq2k
money
funnypic.jpg
quake
Year2K
Mirc2K
Word2001
FunStuff
WindowsMe
extensions:
.vbs
.vbe
.txt.vbs
.jpg.vbs
.avi.vbs
.scr.vbs
Technical Details
The VB script multiplies itself as winuser.dll and user32.dll.vbs in Windows system directory.
The virus also ensures that the script is run by every system start. The registry entry for this is:
user32=wscript.exe
%Windows-System-Verzeichnis%\user32.dll.vbs % HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Then the virus checks if it has been sent by email using Outlook Address Book. This is marked in the registry:
HKCU\software\Guorm, bookmark mailed.
Then the virus scans all drives for mIRC program. In the directories containing the files
mirc.ini
mirc32.exe
mlink32.exe
it replaces and/or creates the file script.ini.
This only happens if the scanning has not been performed before (the bookmark Mirqued in the registry key HKCU\software\Guorm does not exist). Using this ini file, the virus sends itself through IRC.
Kurzfassung
hier
.
Beschreibung erstellt von Crony Walker am Tue, 15 Jun 2004 14:00 (GMT+1)
»
Über Malware
»
Über Phishing
»
In-the-Wild-Viren
« zurück
Diese Seite drucken
Worm/Netsky.HB
TR/Crypt.CFI.Gen
Worm/Netsky.D.Dam
W32/Elkern.C
Worm/Mytob.HA
Halifax 26
TR/Vundo.GJ
TR/Agent.Abt.3
Halifax 25
TR/Dldr.PurityScan.FK
Einfach aktuelle Nachrichten von Avira bekommen, als
Erkennt und entfernt folgende Malware und ihre Varianten:
Worm/Sober.J
Worm/Sober.P
Worm/Sober.Y
W32/Stanit.A
Worm/NetSky.AA
Worm/NetSky.B.1
Worm/NetSky.C
Worm/Netsky.D.Dam
Worm/NetSky.P
Worm/NetSky.X
Worm/Mytob.IN.2
Worm/Mytob.KS
Hier downloaden
"Prozess einer Virenabwehr"
Virenwarnung
auf Ihre Webseite einbinden
© 2008 Avira GmbH
Copyright
Datenschutz
Sitemap
Feedback
Impressum
FAQ
Kontakt