Virus Database


Tver.1000

Description Tver.1000

This is not a dangerous nonmemory resident parasitic virus. It searches for COM files of current directory and directory marked in PATH, then it writes itself to the end of the file. It is nonmemory resident, but leaves a small TSR program that hooks INT 5, waits for the PrintScreen key and drops letters on the screen.

Check other viruses! Be aware! Use Antiviral Software

IRC-Worm.Crack.a

Description IRC-Worm.Crack.a

This is a silly IRC worm spreading through IRC channels by using mIRC client. The worm itself is Win32 executable file about 3K of length (that is compressed executable file, being decompressed it gets about 10K of size).
When the worm file is run, it copies itself to Windows directory with CRACK.EXE name and affects mIRC client. The worm looks for mIRC client in two directories:
C:MIRCD:MIRC
While affecting the worm overwrites the SCRIPT.INI file with a set of commands that send the CRACK.EXE file (worm code) to users that join infected channel.
The SCRIPT.INI file on connecting to IRC server also joins "vxers" and "cservice" channels and sends the messages to there:
To "vxers":
I'm wide awake in my kitchen, it's dark and I'm lonely, oh if I could
only get some sleep.. Creeky noises make my skin creep. I need to get
some sleep.. I can't get no sleepall.
To "cservice":
PLEASE join #vxers, and visit http://www.shadowvx.com/4Q and
http://www.shadowvx.com/fun4vxers .. We're the best!

IRC-Worm.Edoc

Description IRC-Worm.Edoc
This is a simple network worm that replicates in IRC channels. The worm sends the following message to all channel users, except channel operators, that connect to the channel where an infected user is connected:
hey to get OPs use this hack in the chan but SHH!

//$decode(d3JpdGall.........................................................
............................................................................
............................................................................
............................................................................
...................SkgLG0p,m) | $decode( Lmxv........IMQ= ,m)

(dots are placed instead of the virus)
This message contains a line starting from "//", which is a script command and contains the worm's body, encoded with MIME base64 encoding.
If a user receiving the infected message starts the script, the worm creates a file that is then distributed through IRC channels, and adds a link to the infected file in the "mirc.ini" file.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Berufsunfaehigkeitsversicherung
Retro Games
Download Madagascar Dvd
Barnkalas
Greiffs Bilservice

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com