𝔖 Bobbio Scriptorium
✦   LIBER   ✦

32-bit Internet worm ‘Sysid.exe’


Book ID
104391106
Publisher
Elsevier Science
Year
2000
Tongue
English
Weight
156 KB
Volume
2000
Category
Article
ISSN
1353-4858

No coin nor oath required. For personal study only.

✦ Synopsis


C:\windows\ C:\windows\system\ C:\winnt\ C:\winnt\system32\

The virus modifies the registry to load at the next Windows startup. It also writes a VBScript file to the system as WINVER.VBS in an attempt to distribute itself via MAPI Email. It may arrive as one of a large number of attachments (for details see http:// vil.nai.com/villib/dispvirus.asp ?virus_k=98781).

It is possible to detect this virus by its existence in the above-mentioned folders. This Trojan will modify the registry to load at Windows startup after first copying itself to the local system. If MAPI E-mail is available and Windows Scripting Host is installed, it will attempt to send itself via E-mail to several recipients in the Outlook address book.

It is recommended that you use specified engine and DAT files for detection. To remove, boot to MS-DOS mode or use an emergency boot disk and use the command line scanner such as 'SCANPM C: /CLEAN/ALL'.


📜 SIMILAR VOLUMES


32 bits, £32 500
📂 Article 📅 1981 🏛 Elsevier Science 🌐 English ⚖ 124 KB
Collaborative Internet Worm Containment
✍ Min Cai, ; Kai Hwang, ; Yu-Kwong Kwok, ; Shanshan Song, ; Yu Chen, 📂 Article 📅 2005 🏛 IEEE 🌐 English ⚖ 442 KB
32 bit standard
📂 Article 📅 1986 🏛 Elsevier Science ⚖ 377 KB
32 Bit Microprocessors
✍ Standeven, J. 📂 Article 📅 1987 🏛 The Institution of Electrical Engineers ⚖ 198 KB
32-bit sledgehammer
📂 Article 📅 1981 🏛 Elsevier Science 🌐 English ⚖ 109 KB
32-bit CAD
📂 Article 📅 1982 🏛 Elsevier Science 🌐 English ⚖ 73 KB