PE_Chir.B-O |
|
| BugsAlert Home > PE_Chir.B-O | |
|
This memory-resident file infector propagates by sending copies of itself to all addresses listed in the target user's Windows Address Book (WAB). It sends an email with the following format:
From: imissyou@btmail.net.cn It exploits the following vulnerability affecting systems running Microsoft Internet Explorer 5.01 and 5.5:
The said exploit allows the automatic execution of email attachments without the user's consent. For more information, visit the following Microsoft Web page: If the infected system is connected to a network, this file infector also drops copies of its UUEncoded version in shared folders with read and write access. It drops these copies to machines belonging to the same workgroup as that of the infected system. It infects all files with the following extensions:
On the 1st day of the month, it overwrites the first 4,660 Bytes of files with the following extensions:
This file infector is the mother file of PE_CHIR.B. Original Source: http://feeds.trendmicro.com/~r/MalwareTop10/~3/175489018/default5.asp Learn more about PE_Chir.B-O |
|
| Tags: chir.b-o | |
Related Items |
|
|
Fedora update for mt-daapd
|
|
|
CVE-2008-3702 (anigif, download_accelerator_plus)
|
|
|
CVE-2008-1342 (BPM_Suite, CollagePortal)
|
|
|
Fedora update for evolution
|
|
|
FrSIRT - vtiger CRM Multiple Parameter Cross Site Scripting Vulnerabilities
|
|
|
CVE-2008-2726 (Ruby)
|
|
|
Mandriva: Subject: [Security Announce] [ MDVSA-2008:195 ] apache
|
|