Virus Database


DDoS.Win32.Kozog

Description DDoS.Win32.Kozog

This is a Win32 DDoS (Distributed Denial of Service attack) Trojan that was distributed by a hacker (or hackers group) in November 2000. The Trojan was sent as an e-mail message with an attached file.
The message text and header looks as follows:
--------------------------------------------------------
From: World Travel Agency Ltd. [office4@worldtravel.com]
Sent: November 21, 2000 5:31 PM]
To: All tourists and vacationist]
Subject: Celebrate the New Millenium!]

World Travel Agency Ltd.
359 BTC Drive
P.O. Box 134108
Seattle, WA 98108-23
USA

Dear Sir/Madam

Celebrate the New Millenium! Discover the Paradise!

We offer the most attractive package for the New Millenium celebrations you have ever seen.
Pure nature, modern architecture and high technologies are fused to create the perfect resort.
Reasonable prises, correctness, high quality services.
Click on the zip-file below to see our offer!
Make your neighbours envy!

Best Regards,
--------------------------------------------------------
The attached file intends to be displayed as a ZIP archive, but it is a Windows EXE file with the following name:
"OFFER2001.ZIP [many spaces] .EXE"
This is Trojan "installer" that will affect a computer if it is run. Because of a "spaces" trick, it will be displayed as a .ZIP file in many cases, which could deceive a user to open it.
Installation
When the EXE file (Trojan installer) is run, it extracts from itself two more executable files and copies them to the Windows system director with the following names:
MRE.DLL
SOUNDV.EXE
Under Win9x and WinNT, these files are then registered in the auto-run sections in different ways: under WinNT, the Trojan registers a SOUNDV.EXE file in the system registry:
SOFTWAREMicrosoftWindowsCurrentVersionRun soundv.exe
Under Win9x, the DLL file is registered in the SYSTEM.INI file in the following[boot] section:
drivers=mre.dll
The Trojan then displays the following fake error message:
Error
A requred DLL does not exist.

(the grammar mistake is left as it is in the Trojan code).
The SOUNDV.EXE is the DoS Trojan itself. The MRE.DLL is a small program that just executes the SOUNDV.EXE upon each running. As a result, under both Win9x and WinNT, the SOUNDV.EXE component will be activated.
DoS Attack
When this file is run (upon the next Windows restart), it will stay active as a hidden application (service), then it enables the auto-dial option in the Internet settings, then performs a DoS attack on the server "kozirog.netissat.net".

Check other viruses! Be aware! Use Antiviral Software

Areopag.480

Description Areopag.480

It is a not dangerous memory resident parasitic virus. It hooks INT 21h and writes itself at the end of COM-files that are executed. Depending on the system timer, it disables ChangeDir function. It contains the internal text strings:
* Equus Trojanus v1.1 (C) AREOPAG No.15 *

Argentina.1249

Description Argentina.1249

This is a memory resident not dangerous virus which hooks INT 21h and writes itself into the beginning of .COM-files (except COMMAND.COM) when they are started. During infection the virus creates the file MOM.MOM, writes itself into this file, appends a file getting infection to MOM.MOM, deletes the file and renames the MOM.MOM to the file name. If the COMMAND.COM is started the virus checks the current date and on May, 25th, on June, 20th, on July, 9th, on August, 17th the virus types one of the messages:
25 de Mayo Declaración de la independencia Argentina
20 de Junio Dia de la bandera Argentina
9 de Julio Dia de la independencia Argentina
17 de Agosto Aniversario de la defunción del Gral. San Martin

Then virus types:
Argentina Virus escrito por AfA - Virus benigno - ENET 35
Pulse una tecla para continuarall

This virus also contains the texts: "Argentina Virus 1.00", "COMMANDCOM", ":MOM.MOM".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



France Phone Cards
Cash Advance
Webbutik
Car Audio Systems
Dvd Manufacturing

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com