Virus Database


Acapulco.1971

Description Acapulco.1971

It's a not dangerous memory resident parasitic virus. It hooks INT 21h and writes itself at the end of COM- and EXE-files are executed. Sometimes it hooks INT 08h (timer) and plays several tunes.

Check other viruses! Be aware! Use Antiviral Software

IRC-Worm.Crack.a

Description IRC-Worm.Crack.a

This is a silly IRC worm spreading through IRC channels by using mIRC client. The worm itself is Win32 executable file about 3K of length (that is compressed executable file, being decompressed it gets about 10K of size).
When the worm file is run, it copies itself to Windows directory with CRACK.EXE name and affects mIRC client. The worm looks for mIRC client in two directories:
C:MIRCD:MIRC
While affecting the worm overwrites the SCRIPT.INI file with a set of commands that send the CRACK.EXE file (worm code) to users that join infected channel.
The SCRIPT.INI file on connecting to IRC server also joins "vxers" and "cservice" channels and sends the messages to there:
To "vxers":
I'm wide awake in my kitchen, it's dark and I'm lonely, oh if I could
only get some sleep.. Creeky noises make my skin creep. I need to get
some sleep.. I can't get no sleepall.
To "cservice":
PLEASE join #vxers, and visit http://www.shadowvx.com/4Q and
http://www.shadowvx.com/fun4vxers .. We're the best!

IRC-Worm.Edoc

Description IRC-Worm.Edoc
This is a simple network worm that replicates in IRC channels. The worm sends the following message to all channel users, except channel operators, that connect to the channel where an infected user is connected:
hey to get OPs use this hack in the chan but SHH!

//$decode(d3JpdGall.........................................................
............................................................................
............................................................................
............................................................................
...................SkgLG0p,m) | $decode( Lmxv........IMQ= ,m)

(dots are placed instead of the virus)
This message contains a line starting from "//", which is a script command and contains the worm's body, encoded with MIME base64 encoding.
If a user receiving the infected message starts the script, the worm creates a file that is then distributed through IRC channels, and adds a link to the infected file in the "mirc.ini" file.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Drömdejt
Julklappar
Wii Store
Pellets

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com