Main Menu
Home
Bookmark
Contact Us



 
Worm.Bymer. Viruses Information

Name: Worm.Bymer.
Category: Viruses
Description: Details
Worm.Bymer.a

This program is a PE EXE worm (Win32 application). It infects Win9x machines with open file shares. This worm propagates by randomly selecting an arbitrary IP address and attempting to connect to the "C" file share on that machine. If it is successful in accessing that share, it will copy several files into the remote machine's "WINDOWSSYSTEM" directories:
WININIT.EXE ~22016 bytes (body of worm)
DNETC.EXE 186188 bytes (RC5 client)
DNETC.INI (INI-file of DNETC.EXE)
Additionally, as a part of the infection, the following line may be added to the remote computer's WINDOWSWIN.INI file:
[windows]
load=C:WINDOWSSYSTEMWININIT.EXE
After rebooting a victim computer, WININIT.EXE executes DNETC.EXE in a hidden mode and continues infecting another computer.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Victor.244
Macro.Word97.Lulun
K
Worm.P2P.Harex.
N_Xeram.166
I-Worm.Androi
Anarchy.938
Haldeman.43
LionKing.353
BuenDia.81


 


© 2006-2008 spyware32.com - Privacy Policy