|
Subscribe
to Virus Alert |
W32/Lirva.B Worm
W32/Lirva.B is a worm, which infects
Windows systems. It is a variant of W32/Lirva.A.
The worm spreads through email, shared network drives, ICQ,
IRC and KaZaA P2P software. The content of the mail may carry will be any one from the following sets; Set 1 Set 2 Network Associates weekly report: Set 3 AVRIL LAVIGNE - THE CHART ATTACK! Vote fo4r Complicated! Vote fo4r Sk8er Boi! Vote fo4r I'm with you! Chart attack active list: Set 4 Restricted area response team (RART) Attachment you sent to is intended to overwrite start address at 0000:HH4F To prevent from the further buffer overflow attacks apply the MSO-patch " The mail contains an infected attachment, name of the attachment will be chosen from a list of filenames. Upon execution of the infected attachment, it copies itself with hidden attributes, in the root of C: drive and to the Windows temp folder, with EXE and TFT extensions. It also copies itself under Windows System folder with a random file name chosen by the worm. It modifies the registry at the following
location to load itself during the next startup. After this using its own SMTP engine, the worm mails itself to all email addresses found under MBX, EML, HTM, WAB, NCH, HTML, TBB, SHTML, DBX and IDX extension files. In the network shared drive, it copies itself to \RECYCLED folder and modifies the AUTOEXEC.BAT of the target system to load itself during the next startup. If ICQ is installed it sends itself to all the contacts found under contact list. This worm spreads under mIRC by altering SCRIPT.INI. It also spreads under KaZaA P2P environment, by copying itself to KaZaA download folder. It carries a payload. On 7th, 11th and
24th of every month, the worm displays horizontal and vertical elliptical
shapes on the desktop. It also displays the following string; on the upper portion of the screen. The
worm tries to remove background processes of major antivirus software installed
in the infected computer. It also mails the login information of the local
computer's dial-up account to the virus writer. Click
here to download a 30 day Evaluation Copy of |
Proland Software is the developer of Protector Plus range of antivirus software packages. Protector Plus is available for Windows Vista, Windows 95/98/Me, Windows XP, Windows NT/2000/2003 servers and workstations, MS-Exchange 2000/2003, MS-DOS and NetWare servers.
![]() |
|
Protector Plus range of antivirus products
offer on-line virus detection and removal. All the packages have the ability
to detect and isolate all types of viruses, trojans, worms and other types
of malware. Protector Plus antivirus software can detect and remove W32/Lirva.B worm reliably.
These products are updated on a continuous basis and the latest
upgrades for all the platforms are made available for downloading from
this site.
|
You can download the 30 day evaluation
copy of the
antivirus software free of cost for these platforms:
![]()
![]()
![]()
![]()
![]()
![]()
![]()
Copyright ©
2007 Proland Sofrware. All rights reserved.