Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

PE_Chir.B-O

BugsAlert Home > PE_Chir.B-O
 
 

This memory-resident file infector propagates by sending copies of itself to all addresses listed in the target user's Windows Address Book (WAB). It sends an email with the following format:

From: imissyou@btmail.net.cn
Subject: {user name} is comming!
Message: {blank}
Attachment: PP.EXE

It exploits the following vulnerability affecting systems running Microsoft Internet Explorer 5.01 and 5.5:

    Incorrect MIME Header Can Cause IE to Execute Email Attachment

The said exploit allows the automatic execution of email attachments without the user's consent. For more information, visit the following Microsoft Web page:

If the infected system is connected to a network, this file infector also drops copies of its UUEncoded version in shared folders with read and write access. It drops these copies to machines belonging to the same workgroup as that of the infected system.

It infects all files with the following extensions:

  • EXE
  • SCR
  • HTM
  • HTML

On the 1st day of the month, it overwrites the first 4,660 Bytes of files with the following extensions:

  • ADC
  • R.DB
  • DOC
  • XLS

This file infector is the mother file of PE_CHIR.B.




Original Source: http://feeds.trendmicro.com/~r/MalwareTop10/~3/175489018/default5.asp

Learn more about PE_Chir.B-O
 
Tags: chir.b-o

Related Items

      Fedora update for mt-daapd

      CVE-2008-3702 (anigif, download_accelerator_plus)

      CVE-2008-1342 (BPM_Suite, CollagePortal)

      Fedora update for evolution

      FrSIRT - vtiger CRM Multiple Parameter Cross Site Scripting Vulnerabilities

      CVE-2008-2726 (Ruby)

      Mandriva: Subject: [Security Announce] [ MDVSA-2008:195 ] apache

 

Pixel