Main Menu
Home
Bookmark
Contact Us



 
Worm.P2P.VB.b Viruses Information

Name: Worm.P2P.VB.b
Category: Viruses
Description: Details
Worm.P2P.VB.bh

This worm spreads via P2P networks as a PE file.
The worm itself is a Windows PE EXE file, 32KB in size and is written in Visual Basic.
Installation
When launched, the worm copies itself to the C:WindowsSystem32 directory under its current name and hides the file in the Windows system directory.
The worm then registers this file in the system registry, to ensure that the file is launched each time Windows is started:
[HKLMSoftwareMicrosoftWindowsCurrentVersionRun]
Windows =
Propagation
The worm copies itself to the following directories:
C:My Shared FolderC:WindowsMy Shared FolderC:WindowsShareC:My DownloadsC:WindowsMy DownloadsDoS attacks
When launched, the worm conducts DoS attacks on the following sites:
www.microsoft.com
www.aol.com
www.yahoo.com
www.google.com
by sending packets of maximum size (64 bytes) using the ping utility.
It will only do this between 0000 and 1800 and from 1900 to 2400.
Presence in the system
If the worm is launched between 1800 and 1900 according to the local system clock, it will create a directory named Shared in the C: root directory, and will copy itself to this directory.



Top Viruses Visited Pages:
Invader. - 241 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 67 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Macro.PPoint.Kell
Worm.Win32.Flemin
Forger.100
Macro.Word.Ma
TrojanDownloader.Win32.Keenval.
Glew.424
Macro.Access.Lovel
Macro.Word.Trojan.Forma
Pojer.402
GERD.79


 


© 2006-2008 spyware32.com - Privacy Policy