Virus Database


Win32.HLLW.Nulock

Description Win32.HLLW.Nulock

This is dangerous Win32 worm virus written in Delphi, about 300K in length. The worm installs itself into the system, stays in Windows memory as a process (that is visible in task list), and then, with delays (randomly selected from 10 to 20 minutes), copies itself to the A: drive (if there is one inserted).
The worm does not access any other files, and does not spread in any other way.
While installing into the system and copying to the A: drive, the virus generates random names for its copy, for example:
DOLE.EXE, JFMCQRL.EXE, PLNTGS.EXE, ETZBQVT.EXE, JDESH.EXE, WJPIOR.EXE
While installing into the system, the worm copies itself with a random name and .DLL extension to the Windows directory, and registers that copy in the system registry in the auto-run section:
HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun "NumLock"="value"
The key "value" depends on the worm's copy name, for example:
NumLock = "windirdole.dll"
NumLock = "windirjfmcqrl.dll"
NumLock = "windirplntgs.dll"
where "windir" is the Windows directory.
To let Windows to run that DLL file as an ordinary application, the worm also creates the registry key:
HKCRdllfileshellopencommand
and writes to there a value that is standard for running Windows EXE files.
On Tuesdays at 10:30, the virus erases registry files:
USER.DAT, SYSTEM.DAT, USER.DA0, SYSTEM.DA0

Check other viruses! Be aware! Use Antiviral Software

Hex

Description Hex

It's a harmless memory resident boot virus. It hooks INT 13h and writes itself into MBR of hard drive and boot sector of floppy disks. It contains the internal text strings:
CocaColato jest to!
Wirus HEX dedykowany E.D. i M.Sellowi

HeyHunter.1087

Description HeyHunter.1087
This is harmless memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed with DOS calls Execute, Open, Rename, Get/Set File Attributes, FindFirst/Next FCB.
The virus does not manifest itself in any way. It contains the text string:
Hey hunter !all Curse you

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com