I-Worm.Chir.B
I-Worm.Chir.B is still similar to its precedessors. Spammed mails with link in IP format directs users to the worm web pages where the users are prompted to download one of the worm files with the name funny.exe. I-Worm.Chir.B spreading method is similar to Nuwar.L last month propagation. Spammed emails are brief containing link in IP format to currently working pages with worm. Compromised page code is changed and and as a result user is prompted to download file with worm.
Aliases:CVDL W32/Chinese_Hacker.b CyberSoft VFind Security Toolkit
Email-Worm.Win32.Chir.B Ikarus
Email-Worm.Win32.Runouce.b Kaspersky On-Demand Scanner for Linux
Email-Worm.Win32.Runouce.b [AVP] F-Secure Anti-Virus for Linux
I-Worm.Chir.B Central Command / Vexira
PE_Chir.B-O Trend Micro IWSS commandline scanner
W32.Runouce CAT Quick Heal
W32/Chir-B Sophos SWEEP virus detection utility
W32/Chir.b@MM McAfee Virus Scan for Linux
W32/Thecid.B@mm F-PROT ANTIVIRUS for Linux
Win32.Runonce.6652 Doctor Web Ltd, Dr.Web (R) for Linux
Win32.Runouce.6652 VirusBlokAda Vba32
Win32.Runouce.B@mm Bitdefender/Linux-Console
Win32.Runouce.B@mm G Data AVK for Linux
Win32/Chir.B ESET NOD32 on demand scanner for Linux
Win32/Chir.B@mm Grisoft AVG for Linux
Win32:Nimda [Drp ALWIL software avast! antivirus
Worm.Runouce.B MKS_VIR
Worm.Runouce.B Arcavir
Worm.Runouce.b Clam AntiVirus
Worm/RunOnce.B2 worm AVIRA Desktop for UNIX
Need help? Post you problem on Free Malware Remove Help forum
I-Worm.Chir.B Summary
1.Temporarily Disable System Restore;2.Reboot computer in SafeMode;3.delte I-Worm.Chir.B virus files and kill I-Worm.Chir.B file task process(if have);4.Delete/Modify any values added to the registry by I-Worm.Chir.B ;5.delete IE temp files,restart the computer and run a whole scan with Vexira. I-Worm.Chir.B virus files as following:
kindly tell me how can I remove win32 Nimda [drp] virus