Main Menu
Home
Bookmark
Contact Us



 
Win32.IKX.100 Viruses Information

Name: Win32.IKX.100
Category: Viruses
Description: Details
Win32.IKX.1009

It is a harmless nonmemory resident parasitic Win32-virus. It searches for Windows32 PE executable files in the current directory and infects them. The virus works under both Windows 95/98 and Windows NT.
When an infected program is run, the virus receives control and searches for Windows32 API addresses. First of all it scans KERNEL code and looks for GetProcAddress function address. When this function is located, the virus by using this address gets pointers to nine other functions:
CreateFileA, CreateFileMappingA, MapViewOfFile, CloseHandle,
FindFirstFileA, FindNextFileA, FindClose, UnmapViewOfFile, SetEndOfFile

By using these calls the virus then searches for files and infects them. While infection the virus incorporates its code into the middle of the file to the end of first section. The virus looks for gap in the virtual image of file: if there is enough free space between first and second section in virtual image (addresses in the memory, not in disk file - the virus avoids overlapping sections on loading file into the memory), the virus shifts the rest of the file down by 1024 bytes, writes its code into this cave, modifies entry point address and fix section headers.
The virus has a bug that causes double infection. Despite this, infected files work without any problem.
The virus contains the text string that gives its name:
MurkryIKX



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Fruit.162
Xph Famil
Gkchp.80
Compiac.37
Macro.Word.Zoolo
Lazy.72
Ros
Ache.33
Leech.102
Linux.Satyr.


 


© 2006-2008 spyware32.com - Privacy Policy