Main Menu
Home
Bookmark
Contact Us



 
Win32.HLLP.Ime Viruses Information

Name: Win32.HLLP.Ime
Category: Viruses
Description: Details
Win32.HLLP.Imel

This is a Win32 virus infecting Win32 PE EXE files (Win32 applications), spreading via floppy disks. The worm itself is a Win32 PE EXE application written in Visual Basic.
The worm looks for EXE files in the current director, and writes itself to the beginning of the file. The worm then copies itself to two files in the system
C:Game32.exe
C:WINDOWSGame32.exe
The second file is then registered in the auto-run registry key:
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun Imelda = c:WINDOWSGAME32.exe
To spread via floppy disks, the worm copies itself to the A: drive with the A:imel.exe name, and creates an additional A:autoexec.bat file with a command that copies the worm copy from the A: drive to a C:Game32.exe file and to the Windows auto-run directory "c:windowsstartm~1programsstartupGame32.exe"
The worm then displays a "Win32.IMELDA.A" text in the center of the screen.
On the 8th and 12th of any month, the worm creates two links to a Web page and email address on the Desktop:
http://www.indovirus.8m.net
mailto:iwing@iwing-homebase.org
The virus then displays the following message:
Win32.Imelda.A

Hiall There, this is my Day to go Around the world
Just click OK and well do the rest.... :)

Visit me at http://www.indovirus.8m.net or
http://www.geocities.com/indohacker2001,
for serum - Mailto:iwing@iwing-homebase.org



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Warsaw.85
Rushhour Famil
Win32.CTX.688
Macro.Word.Nik
Tib famil
Zhu.174
Sochi.70
DAME.Lame.232
Mbd.125
Worm.Win32.Flemin


 


© 2006-2008 spyware32.com - Privacy Policy