Virus Database


Win32.HLLW.Ayubin

Description Win32.HLLW.Ayubin
This is a virus worm in the form of an executable file for Windows 95/98/Me, compressed using UPX. The file is approximately 170KB in its compressed form and 430 KB when uncompressed. The worm is written in Delphi.
Installation
When first started the worm copies itself to the Windows catalogue under a new name. This name is specified by the virus writer when the worm is being configured. It registers itself in the boot sector 'system.ini':
[boot]
shell=Explorer.exe %name%
How the worm spreads
The worm attempts to copy itself at one-minute intervals to the A: root catalogue under the name 'Las_Porno_del _CBTIS.jpg .exe'.
The Trojan procedure
Once the worm has installed itself successfully it informs the creator of the IP-address of the infected computer through a specific website. When configuring the worm, the author specifies a port number: the worm opens the TCP-port in order to receive commands. Depending on the commands given, the worm performs the following actions:
It forwards system passwords which it has received with the help of the WnetEnumCachedPasswords function
It activates or deactivates the keyboard logger function
It forwards data collected by the keyboard logger
It deletes itself from the infected computer
Other On launching the worm excludes itself from the Windows task list.

Check other viruses! Be aware! Use Antiviral Software

Macro.Word.Apparition

Description Macro.Word.Apparition

This is quite a primitive virus. It is dropped by Windows EXE virus "Win.Apparition". It contains three macros: WWUpdated, AutoOp (AutoOpen), FileOpen.
WWUpdated is the virus ID-macro. The virus detects its presence in the system by using this name. Macro AutoOp (AutoOpen in NORMAL.DOT) installs the virus macros into the system on opening an infected file. Macro FileOpen infects files on opening.
The virus contains the text strings, but does not use them in any way:
Presence of AVP for winword
AVP for Winword is a nice tutorial
(C) 2 Rats Soft.
this macro loaded in normal template as FileOpen
AVPcopyright$ AVP for WinWord v1.0
sQuestion$ Would you like to

Macro.Word.Appder.a

Description Macro.Word.Appder.a

This Word macro virus contains two original macros, but while infecting documents copies them to three macros:
NORMAL.DOT Infected files
Appder -> Appder, AutoOpen
AutoClose AutoClose

The virus infects the global macros area on AutoOpen and writes itself to documents on AutoClose. It also creates the "NTTHNTA=value" line in the "[Microsoft Word]" section in WINWORD6.INI file and increases this value while infecting any document. When this value reaches 20, the virus deletes the files:
C:DOC*.EXE
C:DOC*.COM
C:WINDOWS*.EXE
C:WINDOWSSYSTEM*.TTF
C:WINDOWSSYSTEM*.FOT

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Recipe From Restaurant
Billiga Smycken
Limousinenservice Freiburg
Discover Cards
Tumba FriskvÅrd

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com