Virus Database


I-Worm.Duksten.b

Description I-Worm.Duksten.b

Duksten.b (aka Protex) is a worm virus spreading via the Internet in ZIP files attached to infected emails. The worm itself is a Windows PE EXE file about 10KB in length, encrypted. In infected messages the attached file is a ZIP archive with the name PROTECT.ZIP where the worm copy ProTecT.exe is stored.
The infected messages have an empty body and the following fields:
From:
Subject: ProTeccion TOTAL contra W32/Bugbear (30dias)
Attach: PROTECT.ZIP

The worm activates from infected emails only if a user clicks on the attached file. Doing this extracts the EXE file from the ZIP archive, and runs it. The worm then installs itself to the system and runs its spreading routine and payload.
Installing
While installing the worm copies itself to the Windows system directory with the PrTecTor.exe name and registers this file in the system registry auto-run key:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
XRF = %SystemDir%PrTecTor.exe

The worm then displays a "fake" message:
PrTecTor

Su Pc < -_NO_- > fue infectado por el W32/Bugbear

ProTecTor sera operativo durante 30dias pasado ese tiempo debera ReGistrar su copia siguiendo las instrucciones
att::staff

[ OK ]

"Regedit" stealth
This worm also copies itself to the Windows directory under the name regedit.exe and makes a backup copy of the original REGEDIT.EXE file under the name m_regedit.exe.
When a user starts REGEDIT the worm copy gets control, deletes the worm's "Run" key from system registry, and then executes the original REGEDIT from the "m_regedit.exe" file. When REGEDIT exits, the worm re-installs itself (including in the registry "Run" key).
As a result the worm hides its regitry "Run" key when the REGEDIT utility is run.
Spreading
To get victim email addresses the worm opens the WAB (Windows Address Book) database and reads emails from there. To send infected messages the worm uses a direct connection to the default SMTP server.
There are several bugs in the email spreading routines, therefore the worm has problems spreading itself to "true" SMTP servers that follow email and transfer standards (RFC standards).
While sending infected emails the worm also creates the following files in the Windows system directory:
m_WAB.XRF - this file contains victim email(s)
m_Base64.xrf - worm's ZIP file in MIME form
m_prgrm.zip - worm's ZIP file

While storing itself to the ZIP archive the worm uses a "stored" compression method (i.e. "do not compress" method).
Payload
Starting from January 1st, 2003 the worm reboots victim machines.
Removal
Run the "m_regedit.exe" file from the Windows directory (this is the original REGEDIT utility).
Delete the worm's registry "Run" key (see above).
Reboot the machine and remove the following files from the Windows system directory:
PrTecTor.exe
m_WAB.XRF
m_Base64.xrf
m_prgrm.zip

Next, go to the Windows directory, delete the "regedit.exe" file and then rename the "m_regedit.exe" to "regedit.exe" (doing this restores the original REGEDIT utility).

Check other viruses! Be aware! Use Antiviral Software

HackTool.Win32.CrackSearch.a

Description HackTool.Win32.CrackSearch.a
This program is written in Visual Basic, and is packed using ASPack. The file is approximately 26KB in size. It is designed to find hacker patches, programs which generate serial codes, and other utilities. It is a skin which can be used to search for key words via the search function on http:all

Hadi.6153

Description Hadi.6153

It is not a dangerous memory resident partly encrypted parasitic virus. It hooks INT 8, 9, 20h, 21h and writes itself to the end of COM and EXE files that are executed or closed. The virus is semi-stealth: on opening an infected file the virus disinfects it, on DOS calls FindFirst/Next the virus returns the original length of infected files. When the disk checking utilities are run, the virus disables its stealth routines. The list of these utilities looks as follows: CHKDSK.EXE, SCANDISK.EXE, NDD.EXE, SPEEDISK.EXE, SD.EXE, DEFRAG.EXE. The virus does not infect the files: DEBUG.EXE, TD.EXE, CV.EXE, SI.EXE, NCSI.EXE, SYSINFO.EXE, MSD.EXE, HJ2321.EXE.
Depending on the system date and its internal flags the virus displays the messages:
Hercul Hadi
by Hadi Javan Amirkhizi
03/07/1996
TABRIZ--IRAN
Call me to repair your system (if you find me)
Press CTRL key for 5 seconds to return

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Internet Software Downloads
Computer Utilities Downloads
Webbutveckling
Social Bookmarking

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com