Virus Database


Worm.Win32.Opasoft.s

Description Worm.Win32.Opasoft.s

This worm uses accessible network resources to spread throughout local networks.
The worm file is 17920 bytes in size and packed using ASPack. The unpacked file is approximately 25KB in size.
Symptoms of infection
If a file called srv32.exe is present in the Windows root directory, the computer is infected.
Propagation
When launching, the worm copies itself to the Windows directory as srv32.exe and registers this file in the system registry.
[HKLMSOFTWAREMicrosoftWindowsCurrentVersionRun]
Srv32 =%windir%Srv32.exe
The worm also creates an additional registry key to flag its presence in the system.
[HKLMSOFTWAREMicrosoftWindowsCurrentVersionSRV32]
The worm attempts to copy itself to the Windows root directory on other computers in the local network. It then modifies the win.ini file to ensure that it gains control when the system is rebooted.
Payload
The worm attempts to connect to the site of a Ukrainian mobile services provider
http://sim-sim.com
and send an SMS containing the IP address of the victim machine to 8-050-196XXXX.

Check other viruses! Be aware! Use Antiviral Software

No444.474

Description No444.474

It is a harmless dangerous memory resident parasitic virus. It hooks INT 21h, 2Fh and writes itself to the end of .COM files that are executed. The virus contains a code that erases the MBR of the hard drive, but this code is never executed. The virus contains the text:
* SCHOOL No.444,MOSCOW *

Nobock.440.a

Description Nobock.440.a

It is a dangerous nonmemory resident parasitic virus. It searches for .COM files of the subdirectory tree of the current drive, then writes itself to the end of the file. Sometimes it displays:
No Bock today Error, System halted!

and really halts the system.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Gas Tarif
SjÖlin & HagstrÖm Motor Aktiebolag
Jk Hantverkarna Ab
MGH BYGGPROJEKTERING
Alltid Uppdaterad

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com