Main Menu
Home
Bookmark
Contact Us



 
Win32.Yerg.941 Viruses Information

Name: Win32.Yerg.941
Category: Viruses
Description: Details
Win32.Yerg.9412

This is a relatively harmless, non-memory, resident, parasitic, encrypted Win32 virus. It searches for Win32 EXE applications (PE EXE files) with .EXE and .SCR file name extensions, then infects them.
Upon being run from the A: drive (floppy disk), the virus looks for victim files in the Windows system directory and in all parent directories.
Upon being run from any other drive, the virus looks for files in the current directory and in all parent directories, then on the A: drive.
While infecting, the virus writes itself to the end of the file.
Payload
On the 18th of any month, the virus displays the following message box:

The virus then changes the mouse cursor image (by dropping the new image to the UFO.ANI file and loading the cursor from there - the new image is UFO-like), and then opens the Web page "http://www.abduct.com" that is dedicated to UFOs.
The virus code also contains the following text strings:
YERG
I LOVE YOU DEE
FORGIVE ME DEE
you make me so happy!
if you see this Dee online in the desc i love you
Cell [MATRiX]



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Monster Famil
Maresme.106
Macro.Word.FunFu
DeadWin.122
I-Worm.Stopin.
Hoppit
Sepultura.20
AntiSabados.81
TaiPan.43
MegaF.110


 


© 2006-2008 spyware32.com - Privacy Policy