Win32.HLLW.Ayubin
Description Win32.HLLW.Ayubin This is a virus worm in the form of an executable file for Windows 95/98/Me, compressed using UPX. The file is approximately 170KB in its compressed form and 430 KB when uncompressed. The worm is written in Delphi. Installation When first started the worm copies itself to the Windows catalogue under a new name. This name is specified by the virus writer when the worm is being configured. It registers itself in the boot sector 'system.ini': [boot] shell=Explorer.exe %name% How the worm spreads The worm attempts to copy itself at one-minute intervals to the A: root catalogue under the name 'Las_Porno_del _CBTIS.jpg .exe'. The Trojan procedure Once the worm has installed itself successfully it informs the creator of the IP-address of the infected computer through a specific website. When configuring the worm, the author specifies a port number: the worm opens the TCP-port in order to receive commands. Depending on the commands given, the worm performs the following actions: It forwards system passwords which it has received with the help of the WnetEnumCachedPasswords function It activates or deactivates the keyboard logger function It forwards data collected by the keyboard logger It deletes itself from the infected computer Other On launching the worm excludes itself from the Windows task list.
Check other viruses! Be aware! Use Antiviral Software
Macro.Word.Apparition
Description Macro.Word.Apparition
This is quite a primitive virus. It is dropped by Windows EXE virus "Win.Apparition". It contains three macros: WWUpdated, AutoOp (AutoOpen), FileOpen. WWUpdated is the virus ID-macro. The virus detects its presence in the system by using this name. Macro AutoOp (AutoOpen in NORMAL.DOT) installs the virus macros into the system on opening an infected file. Macro FileOpen infects files on opening. The virus contains the text strings, but does not use them in any way: Presence of AVP for winword AVP for Winword is a nice tutorial (C) 2 Rats Soft. this macro loaded in normal template as FileOpen AVPcopyright$ AVP for WinWord v1.0 sQuestion$ Would you like to
Macro.Word.Appder.a
Description Macro.Word.Appder.a
This Word macro virus contains two original macros, but while infecting documents copies them to three macros: NORMAL.DOT Infected files Appder -> Appder, AutoOpen AutoClose AutoClose
The virus infects the global macros area on AutoOpen and writes itself to documents on AutoClose. It also creates the "NTTHNTA=value" line in the "[Microsoft Word]" section in WINWORD6.INI file and increases this value while infecting any document. When this value reaches 20, the virus deletes the files: C:DOC*.EXE C:DOC*.COM C:WINDOWS*.EXE C:WINDOWSSYSTEM*.TTF C:WINDOWSSYSTEM*.FOT
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Recipe From Restaurant Billiga Smycken Limousinenservice Freiburg Discover Cards Tumba FriskvÅrd
|