x
48h OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
SPECIAL OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
HALLOWEEN OFFER
take advantage of our
terrific discounts
BUY NOW AND GET A 50% OFF
x
CHRISTMAS OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 40% OFF
x
SPECIAL OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 50% OFF
x
BLACKFRIDAY OFFER
Buy the best antivirus
at the best price
TODAY ONLY UP TO 70% OFF
x
CYBERMONDAY OFFER
Buy the best antivirus
at the best price
(Only for homeusers)
TODAY ONLY UP TO 70% OFF
Active Scan. Scan your PC free
Panda Protection

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Oror.G

Threat LevelModerate threatDamageHighDistributionNot widespread
Common name:Oror.G
Technical name:W32/Oror.G
Threat level:Low
Type:Worm
Effects:  It deletes all of the files in every disk drive (both local and accessible network drives). It finds and eliminates antivirus program files.
Affected platforms:

Windows XP/2000/NT/ME/98/95

Detection updated on:Nov. 6, 2002
StatisticsNo
Family:OROR

Brief Description 

    

Oror.G is a dangerous worm that deletes all of the files in the computer's hard disk as well as every network drive accesible from the infected machine. It also looks for antivirus program files in order to eliminate them.   

Although Oror.G can spread very quickly through different means, it is more likely to spread by e-mail:

  • E-mail: the worm activates when the file attached to the message is opened or when the e-mail is viewed through Outlook's Preview pane. This is due to the fact that Oror.G takes advantage of the Exploit/iFrame vulnerability.
  • IRC chat.
  • A file sharing application called KaZaa.

Oror.G is difficult to recognize because it is hidden in e-mail messages with variable characteristics. However, it is possible to recognize when it activates, as it displays a fake error message with the title Error Starting Program.

Visible Symptoms 

    

It is difficult to know if Oror.G has reached your computer, as the e-mail message that carries it has variable characteristics. However, this message includes any of the following files: YAHOO Toolbar.EXE, IE_0276_SETUP.EXE, IE50_032.EXE or IE_0274_BG.EXE.

The most evident symptom of infection that reveals the worm's presence on the system and activation is the fact that, once run, it displays the following fake error message on screen: