Main Menu
Home
Bookmark
Contact Us



 
Worm.P2P.Harex. Viruses Information

Name: Worm.P2P.Harex.
Category: Viruses
Description: Details
Worm.P2P.Harex.c

This is a peer-to-peer worm, also known as Exebat. The worm file is about 2 KB in size, packed with FSG. The unpacked file is 17 KB in size.
Installation
During installation the worm creates a folder named "sys32" in the Windows system folder and copies itself to this folder under one of the following filenames:
All Adobe Products Keygen.exe
All Macromedia Products Keygen.exe
All Microsoft Products Keygen.exe
BurnDvds.exe
Divx Pro 5.1 Serial.exe
Dvd Plus Crack.exe
Dvd Ripper.exe
Dvd To Vcd.exe
Dvd Wizard Pro Crack.exe
Dvd Xcopy Crack.exe
DvdCopyOne Crack.exe
DvdToVcd Crack.exe
Easy Dvd creator Crack.exe
Easy Dvd Ripper.exe
EZ Dvd Ripper.exe
Nero Burning Rom Crack.exe
Nimo Codec Pack Updater.exe
Xvid Codec Installer.exe
This folder is then registered in the Windows system registry as Local Content for Kazaa and iMesh file sharing systems:
[HKCUSoftwareKazaaLocalContent]
[HKCUSoftwareKazaaTransfer]
"dir0"="012345:%Windir%systemsys32"

[HKCUSoftwareiMeshClientLocalContent]
"dir0"="012345:%Windir%systemsys32"
Other details
As two previous Harex variants did, this worm downloads a file from the server cnet.0catch.com, saves it in the root folder of drive C: as autoexec.bat.Exe and executes it.



Top Viruses Visited Pages:
Invader. - 241 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 67 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
EICAR-Test-Fil
BrokenHeart.44
Badguy Famil
Am.74
Pages Famil
Macro.Excel.Emperor.
Girls.182
Macro.Word.Hikma
Cossiga.883.
I-Worm.Sober.


 


© 2006-2008 spyware32.com - Privacy Policy