Main Menu
Home
Bookmark
Contact Us



 
Em.130 Viruses Information

Name: Em.130
Category: Viruses
Description: Details
Em.1303

These are dangerous non-memory resident encrypted parasitic viruses. While executing an infected EXE file, the virus opens the C:AUTOEXEC.BAT file, reads the file contents, searches for the line which begins with "path" or "PATH" strings, and inserts the line "em" as the next line:
all
PATH= ...
em
...

Then the virus creates a C:EM.COM file, and writes the encrypted virus body (1303 bytes) there, so the virus creates its COM dropper. Then the virus returns control to host EXE file.
While executing the virus dropper EM.COM (when "infected" AUTOEXEC.BAT receives the control), the virus searches for all .EXE files on the C: drive, and writes itself at the files' end.
On the 28th of any month, the virus summons the trigger routine, which scans the disk for all directory objects (files, subdirectories and volume labels) by using the absolute disk read/write functions INT 25h/26h, and replaces the first letter of the objects name with a SPACE character (20h); after such a correction, DOS cannot access these files/subdirectories.
The virus contains the following internal text strings:
path
PATH
em.com c: autoexec.bat c:*.* *.exe



Top Viruses Visited Pages:
Invader. - 241 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 67 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Hellfire.104
Macro.Word97.Jim.
Bravo!.50
Macro.Word97.Trojan.Tvangest
TrojanProxy.Win32.Webber.
I-Worm.Sin
Oxan.71
King.18
Samp
Tack Famil


 


© 2006-2008 spyware32.com - Privacy Policy