This is a mass-mailing worm that arrives in an email message as follows:
-The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
-The message contains Unicode characters and has been sent as a binary attachment.
-Mail transaction failed. Partial message is available.
From: (spoofed)
Subject: (Random)
Body: (Varies, such as)
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
The message contains Unicode characters and has been sent as a binary attachment.
Mail transaction failed. Partial message is available.
Attachment: (varies .exe, .pif, .cmd, .scr - often arrives in a ZIP archive) (22,528 bytes)
When this file is run it copies itself to the local system with the following filenames:
-c:\Program Files\KaZaA\My Shared Folder\activation_crack.scr
-%SysDir%\taskmon.exe
-(Where %Sysdir% is the Windows System directory, for example C:\WINDOWS\SYSTEM)
It also uses a DLL that it creates in the Windows System directory:
-%SysDir%\shimgapi.dll (4,096 bytes)
It creates the following registry entry to hook Windows startup:
-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run "TaskMon" = %SysDir%\taskmon.exe
The worm opens a connection on TCP port 3127 suggesting remote access capabilities
Indications of Infection:
-Upon executing the virus, Notepad is opened, filled with nonsense characters.
-Existence of the files and registry entry listed above
This file tries to spread via email and by copying itself to the shared directory for Kazaa clients if they are present.
The mailing component harvests address from the local system. Files with the following extensions are targeted:
.wab, .adb, .tbb, .dbx, .asp, .php, .sht, .htm, .txt
Additionally, the worm contains strings, which it uses to randomly generate, or guess, addresses.
4๐ 3๐
1: A very strange phenomena that causes infected victims to become obsessed with the sorceress Schala from Chrono Trigger. The first infected one was supposedly Ozznova,but OniTTRay coined the term.
2: A growing shared account on GameFAQs.com
You see that guy over there with the Schala-Marle doujinshi? He must have the Schala Virus!
The other day TTRay was nice enough to give me the pas to the Schala Virus.
7๐ 11๐
The name you give to a person that isn't really wanted among a group of friends
Gina is giving us the T-Virus.
15๐ 31๐
A nickname for the Covid-19 Virus. Many claim it to be offensive or racist, these people forget that the Spanish Flu was named after a place where it DIDN'T originate.
Kyle: "Bro Kyle got the Chinese Virus!"
Kyle: "You can't say that, DAS RACIST!"
Kyle: "Why the fuck are we all named Kyle?"
61๐ 180๐
A Virus in resident evil:Degeneration movie
Known as the Gyro Virus(i think)
The G-Virus Is On The 4th Floor
6๐ 11๐
Taki Virus is where you add dots to things.
Boy: "Hey.......How..are....you?"
Girl: "Hello. Why are you talking like that?"
Boy: "....I have..Taki Virus..."
2๐ 2๐
A Really Old Virus (probably form the 70's) which make the host spontaneously dance disco and wear flat heels and start snaping their fingers and saying "groovy"
Person 1: Wanna go Bowling
Person 2: Groovy
Person 1: Call 911, we got a guy here with a retro virus.
4๐ 4๐