Virus.Win32.Jolla.a, W32/Zelly.a, Win32.Vallez.18772
W32/Zelly-A, PE_ZELLY.A, W32/Jolla.A, W32/Zelly.A, CRYPT.WIN32
Category: Computer Virus
Active & Spreading
Asia, North and South America, and some parts of Europe and Australia
The W32/Zelly program is a parasitic file infector that affects Windows Operating System such as Windows 2000, Windows 98, Windows 95, Windows NT, Windows Server 2003, Windows Me, and Windows XP.
W32.Zelly Removal Tool
If you have Malware on your computer it will cause annoyances and will damage your system. You should either:
A. Manually remove the infected files from your computer, or
B. Automatically scan your system using trusted software
We recommend that you scan your system for malware. Our partner has a computer virus removal tool to automatically clean W32.Zelly from your computer.
More details about W32.Zelly
When W32.Zelly runs, it displays a message box that contains a message “this file is infected with Win32.JollyRoger” then tries to infect files in your current directory. It will randomly select between two infection modes such as single-section/EPO and dual-section. In the dual section infection mode, the Zelly appends in to two sections to the host file and these are the decryptor of the virus and the encrypted virus body. Then it redirects the entry point of the host into the virus decryptor. In the single section/EPO, W32/Zelly merges all sections of the host file to one section.W32.Zelly attaches numerous polymorphic decryptors, a random amount of padding, and the encrypted virus body.
The system infected by the W32.Zelly program can also be made to participate in Denial of Service (DoS) attacks. These attacks involve sending large amounts of malformed and repeated data to remote machines. The receiving server will be unable to process the information. This will cause the computer to crash. Targets of these attacks often host websites or chatting servers. This software can also install other malicious files into the system. This can include adware, spyware, and Trojan programs.