Virus Database


Win32.HLLW.Scareg

Description Win32.HLLW.Scareg

Scareg is a worm virus spreading through removable drives (i.e. floppy disks, zip disks etc.). The worm itself is a Windows PE EXE file about 372Kb in size, written in Delphi.
The worm installs itself into the system twice.
First, it moves the original SCANREGW.EXE file from the Windows directory to the Windows system directory:
WindowsSCANREGW.EXE -> WindowsSYSTEMSCANREGW.EXE
and overwrites the original SCANREGW.EXE file with its (worm) copy.
Second, the worm copies itself to Windows directory under the name: MEDIAIDH_001.exe
The worm then creates or modifies the existing registry auto-run key:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun
ScanRegistry = %WindowsDir%Scanregw.exe
To spread further the worm gets the list of all removable drives (floppy disks, zip drives etc.) and copies itself there under the name HDD.EXE.

Check other viruses! Be aware! Use Antiviral Software

Kate.582

Description Kate.582

These are harmless memory resident parasitic viruses. They hook INT 21h and write themselves to the end of COM files that are executed or opened. The viruses contain partly encrypted text strings:
"Kate.582": KATE 1.01b - ORIEL software company
"Kate.585": KATE 1996 - (C) ORIEL software company

Katvir.623

Description Katvir.623

It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. It contains the text strings:
Dzieciatka wylewaja niewinnie lzy
bo czuja nieszczescie
choc go nie pojmujaall - KatVir by Warlock from III LO in Olkusz!
KAT

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



BO OSCARSSONS FÖRVALTNING AB
Lundgrens Skorstensservice I Stockholm
T2 PLATTSÄTTNING AB
Bil-el I NorrkÖping MÄhrle
Bergelin, Rolf Stig Lennart

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com