Main Menu
Home
Bookmark
Contact Us



 
Em.130 Viruses Information

Name: Em.130
Category: Viruses
Description: Details
Em.1303

It is a dangerous not memory resident encrypted parasitic virus. While execution of infected EXE-file the virus opens the C:AUTOEXEC.BAT file, reads the file contents, searches for the line which begins with "path" or "PATH" strings, and inserts the line "em" as the next line:
all
PATH= ...
em
...

Then the virus creates the C:EM.COM file and writes the encrypted virus body (1303 bytes) into there, so the virus creates its COM-dropper. Then the virus returns the control to the host EXE-file.
During execution of the virus dropper EM.COM (when "infected" AUTOEXEC.BAT receives the control) the virus searches for all .EXE-files on C: drive and writes itself to the files end.
On 28th of any month the virus calls the trigger routine. That routine scans the disk for all directory objects (files, subdirectories and volume labels) by using absolute disk read/write functions INT 25h/26h, and replaces the first letter of the objects name with SPACE character (20h), after such correction DOS cannot access these files/subdirectories.
The virus contains the internal text strings:
path
PATH
em.com c: autoexec.bat c:*.* *.exe



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Day24.79
Macro.Word97.Inexist.
Daga.91
Kontragap
Buffalo.48
Indi
Win95.Rekoj.940.
Macro.Word.Sca
Antimit.77
CodeBreaker.43


 


© 2006-2008 spyware32.com - Privacy Policy