Main Menu
Home
Bookmark
Contact Us



 
WinHLP.Dem Viruses Information

Name: WinHLP.Dem
Category: Viruses
Description: Details
WinHLP.Demo

This is the first known "native" Windows32 HLP files infector, it does function and replicate as a Windows Help script embedded in help file structure (the first known virus affecting Windows HLP files was the "Win95.SK" infector).
When infected HLP file is opened, the Windows Help system processes virus script and executes all functions placed there. By using a trick the virus forces Help system to execute a specially prepared data as binary Windows32 program, these data are included in one of instructions in the virus script. These data themselves are the "start-up" polymorphic routine that builds the main infection routine and executes it. The infection routine is a valid Windows32 procedure, and it is executed as a Windows32 application.
When infection routine takes control, it scans Windows kernel (KERNEL32.DLL image loaded in Windows memory) in usual for Win32 executable files parasitic infectors, and gets addresses of necessary Windows functions from there. The infection routine then looks for all Windows Help files in the current directory, and infects them all.
While infecting the virus modifies internal HLP file structure, adds its script to the "SYSTEM" area, converts its code to polymorphic start-up routine and includes it into the script.
Before run its infection routine, and when infection is finished, the virus displays the MessageBoxes:
HLP.Demo
Trying to infect
HLP.Demo
Script comes to end!



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Win32.HLLO.Roza
Lamah.56
Trojan.Java.Nochea
Christ.48
I-Worm.Sexer.
PolyEngineSGen.DSC
WildLicker.337
Trojan.Win32.Filecoder.
NetBios.434
Macro.Word.Pakis


 


© 2006-2008 spyware32.com - Privacy Policy