Win32.HLLW.Scareg
Description Win32.HLLW.Scareg
Scareg is a worm virus spreading through removable drives (i.e. floppy disks, zip disks etc.). The worm itself is a Windows PE EXE file about 372Kb in size, written in Delphi. The worm installs itself into the system twice. First, it moves the original SCANREGW.EXE file from the Windows directory to the Windows system directory: WindowsSCANREGW.EXE -> WindowsSYSTEMSCANREGW.EXE and overwrites the original SCANREGW.EXE file with its (worm) copy. Second, the worm copies itself to Windows directory under the name: MEDIAIDH_001.exe The worm then creates or modifies the existing registry auto-run key: HKLMSoftwareMicrosoftWindowsCurrentVersionRun ScanRegistry = %WindowsDir%Scanregw.exe To spread further the worm gets the list of all removable drives (floppy disks, zip drives etc.) and copies itself there under the name HDD.EXE.
Check other viruses! Be aware! Use Antiviral Software
Kate.582
Description Kate.582
These are harmless memory resident parasitic viruses. They hook INT 21h and write themselves to the end of COM files that are executed or opened. The viruses contain partly encrypted text strings: "Kate.582": KATE 1.01b - ORIEL software company "Kate.585": KATE 1996 - (C) ORIEL software company
Katvir.623
Description Katvir.623
It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. It contains the text strings: Dzieciatka wylewaja niewinnie lzy bo czuja nieszczescie choc go nie pojmujaall - KatVir by Warlock from III LO in Olkusz! KAT
|