Virus Database


I-Worm.Lohack.a

Description I-Worm.Lohack.a

This is a virus-worm that spreads via the Internet attached to infected e-mail. The worm itself is a Windows PE EXE file about 15Kb in length (compressed by UPX, decompressed size is about 41K), and it is written in Microsoft Visual C++.
Infected messages consist of the following:
Subject: Hacking courseall
Body: Look the hacking course - version 1.0 !
By Senna Spy - Made In Brazil
http://www.avpavp.hpq.com.br
Attachment: hacking.exe

The worm is activated from infected e-mail only when a user clicks on the attached file.
The worm does not install itself to the system and is not activated anymore (except in cases when a user clicks on the attached e-mail again).
To send infected messages, the worm scans the Windows directory and all subdirectories, and looks for files with the following extensions:
.IDX .NCH .MDX .DBX .MSG .EML .TXT .HTM
Then it looks for e-mail addresses in these files (text strings that are e-mail addresses), then sends infected messages to these addresses. To send infected messages, the worm uses Windows MAPI functions.

Check other viruses! Be aware! Use Antiviral Software

Mity.1982

Description Mity.1982

It is not a dangerous memory resident multipartite virus. When an infected file is executed, the virus writes its code to the last sectors of C: drive and modifies the disk partition table in such way, that active boot sector address points to the virus code (see "Starship" virus). The virus then returns to the host program.
While booting from infected disk the virus hooks INT 13h, waits for DOS loading process, hooks INT 21h and then infects COM and EXE files that are executed. The virus writes itself to the beginning of COM file and to the middle of EXE files.
Depending on its counters the virus displays the text:
XXXX XXXX XXXXXXXX XXXXXXXXXX XXX XXX
XXXXXX XXXXXX XXXXXXXX XXXXXXXXXX XXXXX XXXXX
XXXXXXXXXXXXXXX XXXX XXXX XXXXXXXXX
XXXX XXX XXXX XXXX XXXX XXXX
XXXX XXXX XXXX XXXX XXXXX
XXXX XXXX XXXX XXXX XXXXX

Mix.2280

Description Mix.2280

This is a dangerous encrypted memory-resident parasitic virus. It hooks INT 8, 9, 14h, 17h, 21h and writes itself to the end of COM files that are loaded into the memory.
The virus contains the text:
Strike the pauseVogue, you got to Let your body move with the music
I can leave you , say goodbye , i can love u if i try all...
Left to my own devices i probely could.
The virus manifests itself by changing some characters as they are sent to COM or LPT ports. It changes background color when Ctrl-Alt-Del are pressed, causes "characters falling", or launches a ball, bouncing around the screen frame. An infected file contains the text "Mix1" or "Mix2" at its end.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Social Bookmarking
Spinal Stenosis Treatmeant

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com