Melissa (computer virus)

Melissa (computer virus)

The Melissa virus, also known as "Mailissa", "Simpsons", "Kwyjibo", or "Kwejeebo", is a mass-mailing macro virus. As it is not a standalone program, it is not a worm.

Contents

History

First found on March 26, 1999, Melissa shut down Internet mail systems that got clogged with infected e-mails propagating from the virus. Melissa was not originally designed for harm, but it overloaded servers and caused problems.[citation needed]

Melissa was first distributed in the Usenet discussion group alt.sex. The virus was inside a file called "List.DOC", which contained passwords that allow access into 80 pornographic websites. The virus' original form was sent via e-mail to many people.

David L. Smith

Melissa was written by David L. Smith in Aberdeen Township, New Jersey, and named after a Miami stripper that David had met. The creator of the virus called himself Kwyjibo, but was shown to be identical to macrovirus writers VicodinES and Alt-F11 who had several Word-files with the same characteristic Globally Unique Identifier (GUID), a serial number that was earlier generated with the network card MAC address as a component. Smith was sentenced to 10 years but served only 20 months in a federal prison and fined $5,000 United States dollars. [1] This arrest was a result of collaboration between the FBI, New Jersey State Police and Monmouth Internet.[2] Smith would later go on to help the FBI in tracking down Jan de Wit, the Dutch creator of the Anna Kournikova Computer virus.[3]

Virus specifications

Melissa can spread on word processors Microsoft Word 97 and Word 2000 and also Microsoft Excel 97, 2000 and 2003. It can mass-mail itself from e-mail client Microsoft Outlook 97 or Outlook 98.

If a Word document containing the virus, either LIST.DOC or another infected file, is downloaded and opened, then the macro in the document runs and attempts to mass mail itself.

When the macro mass-mails, it collects the first 50 entries from the alias list or address book and sends itself to the e-mail addresses in those entries.

Melissa.V

This is another variant of the original Melissa macro virus, and is akin to Melissa.U. It uses Microsoft Outlook, and tries to send itself to the first 40 addresses in Outlook's address book. The subject line of the infected e-mail sent out is: "My Pictures (<Username>)", where <Username> is the name to whom the sender's copy of Microsoft Word is registered.

There is also a variant of the virus named Melissa.V/E which is known to seek and destroy Microsoft Excel documents, randomly deleting sets of data from files, or, at the worst, making them completely useless by applying a set of malicious Macro code. To simplify the code, the author has encrypted only a vectorial search pattern in it, so the virus can only delete linear sets of data, usually random rows or columns in a table. It also has a search parameter that makes it go only for unique sets of data, known to cause more damage.

A later edit of this variant makes backup copies of the destroyed files, and asks for a ransom of $100 to be transferred into an offshore account in return for the files. The account has been traced back to the owner. Due to a malfunction in code, in less than 1% of cases the code still makes copies.

This virus was rendered obsolete when it was discovered that it leaves visible traces in the Windows Registry, providing enough data to ensure its destruction and the retrieval of stolen data.

A special version of this variant also modifies the backed-up data, fooling the user even more. It searches for numeric data inside the files, and then, with the help of a random number generator, slightly modifies the data, not visibly, but making it useless.

There is no body to the email, but there is an infected document attached. If this is opened, the payload is triggered immediately. It tries to delete data from the following (local or network) destinations: F:, H:, I:, L:, M:, N:, O:, P:, Q:, S:, X:, and Z:.

Once complete, it beeps three times and then shows a message box with the text: "Hint: Get Norton 2000 not McAfee 4.02".

Melissa.W

Melissa.W does not lower macro security settings in Word 2000. Otherwise it is functionally equal with Melissa.A.

Melissa.AO

This is what the e-mails from this version contain:

Subject: Extremely URGENT: To All E-Mail User - <current date>
Attachment: <Infected Active Document>
Body: This announcement is for all E-MAIL user. Please take note
that our E-Mail Server will down and we recommended you to read
the document which attached with this E-Mail.

Melissa.AO's payload occurs at 10 a.m. on the 10th day of each month. The payload consists of the virus inserting the following string into the document: "Worm! Let's We Enjoy."

See also


Notes and references

Sources/external links


Wikimedia Foundation. 2010.

Игры ⚽ Поможем сделать НИР

Look at other dictionaries:

  • Melissa (computer worm) — The Melissa worm, also known as Mailissa , Simpsons , Kwyjibo , or Kwejeebo , is a mass mailing macro virus, hence leading some to classify it as a computer worm.HistoryFirst found on March 26, 1999, Melissa shut down Internet mail systems that… …   Wikipedia

  • Computer fraud — is the use of information technology to commit fraud. In the United States, computer fraud is specifically proscribed by the Computer Fraud and Abuse Act, which provides for jail time and fines. Contents 1 Notable incidents 2 See also 3 External… …   Wikipedia

  • Melissa (disambiguation) — Melissa is a given name for a female, meaning honey bee in Greek. Melissa may also refer to: Contents 1 People 2 Places 2.1 Canada …   Wikipedia

  • Computer fraud case studies — BackgroundThe purpose of this page is to explore case studies in using Information Technology to commit fraud. Computer fraud is the act of using a computer to commit fraud (A deception deliberately practiced in order to secure unfair or unlawful …   Wikipedia

  • Virus (informatique) — Virus informatique  Pour l’article homonyme, voir Le Virus informatique.  Cet article fait partie de la série Programmes malveillants …   Wikipédia en Français

  • Virus hoax — A computer virus hoax is a message warning the recipient of a non existent computer virus threat. The message is usually a chain e mail that tells the recipient to forward it to everyone they know. Contents 1 Identification 2 Action 3 List of… …   Wikipedia

  • Melissa — me·lis·sa || mɪ lɪsÉ™ n. female first name; computer virus that infects Word 97 and 2000 files and spreads itself via the Microsoft Outlook email program (Internet) …   English contemporary dictionary

  • List of computer criminals — Hacker Adrian Lamo (left) with contemporaries Kevin Mitnick (center) and Kevin Poulsen …   Wikipedia

  • Computer crime — Computer crime, or cybercrime, refers to any crime that involves a computer and a network.[1] The computer may have been used in the commission of a crime, or it may be the target.[2] Netcrime refers to criminal exploitation of the Internet.[3]… …   Wikipedia

  • Melissa (ver informatique) — Pour les articles homonymes, voir Melissa (homonymie). Melissa est un ver informatique qui a sévi à partir du 26 mars 1999. Cette infection avait deux conséquences : Saturation des systèmes de messagerie Tous les documents infectés d une… …   Wikipédia en Français

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”