English
Deutsch
Francais
Español
Italian
Home
Virus Info
VBS/Guorm
Search
Home
Support
Solutions
Products
Downloads
Virus Info
Statistics
Phishing Worldmap
VDF History
Virus Science
Submit Sample
Security News
Viruses In the Wild
Company
Press
Partners
Newsletter
VBS/Guorm - VBS script virus
See also
Summary
Full description
Statistics
How would you rate this information?
Worthless
Excellent
Alias:
VBS/Gorum.a
Type:
Worm
Size:
~
Origin:
Date:
05-31-2000
Damage:
Sent by email.
VDF Version:
6.20.00.00
Danger:
Medium
Distribution:
Medium
Distribution
The worm sends itself to all addresses found in Outlook. If Outlook 2000 is installed, the virus sends the following email:
Subject:
You know what it is. ;-P
Body:
Check it out!
Attachment name- formed out of the following text strings:
links
cool
funny
anti-loveletter
guorm
pot
win2k
icq2k
money
funnypic.jpg
quake
Year2K
Mirc2K
Word2001
FunStuff
WindowsMe
extensions:
.vbs
.vbe
.txt.vbs
.jpg.vbs
.avi.vbs
.scr.vbs
Technical Details
The VB script multiplies itself as winuser.dll and user32.dll.vbs in Windows system directory.
The virus also ensures that the script is run by every system start. The registry entry for this is:
user32=wscript.exe
%Windows-System-Verzeichnis%\user32.dll.vbs % HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Then the virus checks if it has been sent by email using Outlook Address Book. This is marked in the registry:
HKCU\software\Guorm, bookmark mailed.
Then the virus scans all drives for mIRC program. In the directories containing the files
mirc.ini
mirc32.exe
mlink32.exe
it replaces and/or creates the file script.ini.
This only happens if the scanning has not been performed before (the bookmark Mirqued in the registry key HKCU\software\Guorm does not exist). Using this ini file, the virus sends itself through IRC.
See a brief description
here
.
Description inserted by Crony Walker on Tue, 15 Jun 2004 14:00 (GMT+1)
»
About Malware
»
About Phishing
»
Viruses In the Wild
« back
Print this page
W32/Elkern.C
Worm/Mytob.AT
Worm/Mytob.U
Worm/Lovgate.W
Worm/Mytob.BF
DR/Agent.abpc
TR/Spy.Banker.okm.2
EXP/MS08-067.C
JAVA/Dldr.Small.A
TR/Spy.Banker.get
Get comfortable up to the minute info from Avira as
Detects and removes the following malware and its variants:
Worm/Sober.J
Worm/Sober.P
Worm/Sober.Y
W32/Stanit.A
Worm/NetSky.AA
Worm/NetSky.B.1
Worm/NetSky.C
Worm/Netsky.D.Dam
Worm/NetSky.P
Worm/NetSky.X
Worm/Mytob.IN.2
Worm/Mytob.KS
TR/Spy.Banker.AATZ
TR/Spy.Banker.AATZ.1
TR/Spy.Banker.AATZ.2
TR/Spy.Banker.AATZ.3
Download here
Click
here
to get the panel...
© 2008 Avira GmbH
Copyright
Privacy
Sitemap
Feedback
Imprint
FAQ
Contact