Worm.P2P.VB.bh
Description Worm.P2P.VB.bh
This worm spreads via P2P networks as a PE file. The worm itself is a Windows PE EXE file, 32KB in size and is written in Visual Basic. Installation When launched, the worm copies itself to the C:WindowsSystem32 directory under its current name and hides the file in the Windows system directory. The worm then registers this file in the system registry, to ensure that the file is launched each time Windows is started: [HKLMSoftwareMicrosoftWindowsCurrentVersionRun] Windows = <file name> Propagation The worm copies itself to the following directories: C:My Shared FolderC:WindowsMy Shared FolderC:WindowsShareC:My DownloadsC:WindowsMy DownloadsDoS attacks When launched, the worm conducts DoS attacks on the following sites: www.microsoft.com www.aol.com www.yahoo.com www.google.com by sending packets of maximum size (64 bytes) using the ping utility. It will only do this between 0000 and 1800 and from 1900 to 2400. Presence in the system If the worm is launched between 1800 and 1900 according to the local system clock, it will create a directory named Shared in the C: root directory, and will copy itself to this directory.
Check other viruses! Be aware! Use Antiviral Software
Opic family
Description Opic family
These are not dangerous nonmemory resident encrypted parasitic viruses. They search for EXE files in current and parent directories, then write themselves to the end of the file. "Opic.745" infects files on C: drive only. Depending on the system date and time the viruses beeps by the PC speaker. The "Opic.727" virus then creates two subdirectories: "Odessa!" and "Opic" and writes to the end of CONFIG.SYS file the text: REM-Odessa Virus (c) Opic [CodeBreakers 98]
The "Opic.745" virus also contains the text: Odessa.B (c) Opic [Codebreakers 1998]
Oppressor.559
Description Oppressor.559
It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are executed. While executing the infected files perform INT 5 (Print Screen) call. The virus contains the text string: Oppressor-B, v0.2905, rev.A, no.95.021, by The Heretic
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Rk Klippet Duo StÄd GÖTEBORGS MARIN CENTER KOMMANDITBOLAG FrisÖr Perparim I Karlskrona Rocio FÖretagsservice
|