This is a virus detection. Viruses are programs that self-replicate recursively, meaning that infected systems spread the virus to other systems, which then propagate the virus further. While many viruses contain a destructive payload, it's quite common for viruses to do nothing more than spread from one system to another.
|
Minimum DAT
4430 (2005-02-18) Updated DAT4438 (2005-03-02) |
Minimum Engine
5.1.00 File Length270,336 |
Description Added
2005-02-18 Description Modified2005-02-18 |
This is a mass-mailing virus that bears the following characteristics:
The virus is proactively detected as New Malware.b with DATs 4232 or higher when heuristic scanning is enabled.
When run, the virus displays a fake error message box "Runtime error '4': String out of bounds".
The virus creates the following files in the Windows system32 directory:
It creates the following registry key in order to load itself at Windows startup:
It copies itself to folder contains "shar" string using the following filenames:
It creates files with long blank file name with ".exe", ".pif" extension.
The virus harvests email addresses from files on local machine, uses its own SMTP engine to send mail. The email sent has the following characteristics:
From: (one of the following sender name)@(collected addresses)
Subject:
(one of the following)
Body: (one of the following )
Attachment: (one of the following file names)
with the following extension:
The virus searches executable files on local machine. It prepends itself to any files found.
The virus terminates a list of antivirus application processes.
Existence of the registry key and files mentioned above.
The virus propagates via SMTP mail and file sharing.
All Users:
Use specified engine and DAT files for detection and removal.