Skip to main content
Skip to main content
Microsoft Security Intelligence
23 entries found. Displaying page 1 of 2.
Updated on Oct 09, 2013

Windows Defender detects and removes this threat.

Win32/Chir is a family of malware. It has both worm and virus components. The worm component spreads via email and spreads by exploiting the vulnerability resolved with the release of Microsoft Security Bulletin MS01-020. The virus component infects .EXE and .SCR files in local and remote drives. It's also been known to edit .HTM and .HTML files stored in your PC so that if these files are opened, the virus is run.

Alert level: high
Updated on Jul 10, 2019
Alert level: severe
Updated on May 05, 2016

Windows Defender detects and removes this threat.

This email worm spreads as an attachment to an email. It can also spread via an infected network or removable drive, such as a USB flash drive. When you open the attachment or file, the worm will run.

The worm can also exploit a vulnerability discussed in Microsoft Security Bulletin MS01-020. This can allow the attachment to automatically open when the email is read or previewed on a vulnerable PC. You should download and use the latest version of Internet Explorer to avoid this vulnerability.

Also detected as: Win32/Chir.B@mm(AVG)
Alert level: severe
Updated on Jul 14, 2006
Win32/Chir.A@mm is a mass-mailing worm. The worm sends a copy of itself as an e-mail attachment to e-mail addresses that it finds on the infected computer and remote shares. The worm runs when a user opens the e-mail attachment. On a computer that has not been patched for the Incorrect MIME Header vulnerability described in Microsoft Security Bulletin MS01-020, the attachment can open automatically under certain conditions.
Also detected as: Win32/Chir.10799(CA)
Alert level: severe
Updated on Jul 10, 2006
Win32/Chir.B@mm is both a network and e-mail worm, as well as a virus. The e-mail worm component sends a copy of itself as an e-mail attachment to addresses that it finds on local and remote drives. Win32/Chir.B@mm also exploits the Incorrect Mime Header vulnerability discussed in Microsoft Security Bulletin (MS01-020). This may cause the e-mail attachment to open automatically when the e-mail is read or previewed on susceptible systems that have not had the MS01-020 security patch installed. Win32/Chir.B@mm infects .EXE and .SCR files on local and remote drives. Win32/Chir.B@mm also drops a copy of itself named readme.eml to folders containing .HTM and .HTML files, then appends malicious JavaScript to the bottom of these .HTM* files to cause them to automatically run the infected readme.eml file when they are opened.
Alert level: high
Updated on Sep 21, 2014
Windows Defender Antivirus detects and removes this threat.
 
This virus can infect your files, making it impossible to open them. It can also show pop-up messages to Chinese users.
 
It spreads via email attachments and infected drives, including USB flash drives. 
Alert level: severe
Updated on Oct 07, 2008
Alert level: severe
Updated on Oct 07, 2008
Alert level: severe
Updated on Oct 07, 2008
Alert level: severe
Updated on Dec 14, 2019
Alert level: severe
Updated on Jul 12, 2021
Alert level: severe
Updated on Oct 26, 2021
Alert level: severe
Updated on Sep 17, 2022
Alert level: severe
Updated on Apr 26, 2023
Alert level: severe
Updated on Sep 04, 2023
Alert level: severe
Updated on Oct 29, 2023
Alert level: severe
Updated on Sep 14, 2016
Alert level: severe
Updated on Apr 11, 2011
Exploit:HTML/IFrame_Exploit.G is a detection for malicious .eml files that attempt to exploit the vulnerability addressed by MS01-020 (Incorrect MIME Header Can Cause IE to Execute E-mail Attachment) in order to launch a malicious binary. In the wild, the use of malicious files identified by this detection have mostly been associated with the Win32/Chir family.
Alert level: severe
Updated on Apr 11, 2011
Trojan:JS/Nimda.A is a trojan that attempts to open the malicious file “readme.eml” in the current folder. The file “readme.eml” is a malformed multipart MIME formatted message file dropped by Worm:Win32/Nimda, and it contains an encoded copy of Worm:Win32/Nimda.
 
Trojan:JS/Nimda.A takes advantage of a vulnerability corrected by MS01-020 (Incorrect MIME Header Can Cause IE to Execute E-mail Attachment).
Also detected as: Win32/Chir.B(ESET)
Alert level: severe
Updated on Apr 11, 2011
Win32/Nimda is a family of worms that targets computers running certain versions of Microsoft Windows. The worm exploits the Windows vulnerability described in Microsoft Security Bulletin MS01-020 in order to spread by infecting Web-content documents and attaching itself to e-mails. The worm also spreads by infecting executable files and by copying itself to local folders, network shares, and remote computers through backdoors. The worm compromises security by sharing the C drive and creating a Guest account with administrator permissions.
Alert level: severe