Virus Protection > computer-virus-i-page1 > - i-worm.hermes.

i-worm.hermes.

Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.

Description: Details
I-Worm.Hermes.a

This is email worm spreading by affecting MS Outlook. The worm itself is Win32 executable file about 20K of length (the worm body is compressed, being decompressed it occupies about 60K). The worm is written in Visual Basic language.
The worm connects to MS Outlook by using MAPI functions, gets all addresses from Address Book and sends messages to them. The messages have:
Subject: Re:
Text: [%SenderName%]
where %SenderName% is name of sender (current user email account name).
The attach name is randomly selected from variants:
Seti@home 3.x to 4.0 upd.exe
Seti@home_twk.exe
Seti_patch.exe
Lunetic!.exe
CIH.exe
Energy.exe
ftip.exe
Navidat.exe
Click_ME!.exe
Cenik.exe
Lunetic.scr
fucking.scr
micro$haft.scr
matrix.scr
reboot.scr
Pamela.scr
techno.scr
funny!.scr
Hermes.scr
School_in_da_flame.scr
The worm also displays the message boxes:
_ i-Worm.Hermes _
Code by: gl


This program requires more conventional memory
Unload drivers or memory-resident programs that use conventional memory,
or increase the value for Minimum Conventional Memory in the program's
Memory properities sheet.
The worm also connects the "http://www.seznam.cz" Web site, but does nothing in there.
The worm also tries to write registry keys but fails because of a bug.

Updated: 02/24/2006
Copyright @2006 i-worm.hermes.
Webroot Software Inc.