| 1. | P2P-Worm.Win32.Achar.a
This is a family of harmless worms that replicate by making their copies in a Kazaa shared folder.
The worm is a Windows application (PE EXE file) written in Assembler, the worm file size is
about 8K.
The worm does not install itself into the system.
To infect Kazaa shared folder the worm reads...
|
| 2. | P2P-Worm.Win32.Bare.a
Bare is an Internet worm that spreads in the Kazaa, Morpheus, BearShare and eDonkey2000 peer-to-peer file exchange networks. The worm replicates by placing copies of itself in the shared folders used on the client machines comprising these networks.
The Bare worm is a Windows application (PE EXE...
|
| 3. | P2P-Worm.Win32.Benjamin.a
This worm uses the Kazaa file exchange P2P network to spread itself. The Kazaa network allows its users to exchange files with each other using the Kazaa client software. To learn more about the Kazaa network visit their site at: http://www.kazaa.com.
Benjamin is written in Borland Delphi and is...
|
| 4. | P2P-Worm.Win32.Darby.m This worm spreads via the Internet via file-sharing networks. It also spreads via IRC channels, open network resources, and as an attachment to infected messages. It sends itself to addresses harvested from the victim machine.
The worm itself is a Windows PE EXE file approximately 141KB in size,...
|
| 5. | P2P-Worm.Win32.Duload.a Worm.P2P.Duload represents a family of worms that replicate by copying themselves into a Kazaa network shared folder located on victim machines.
The worm itself is a Windows application (PE EXE file) written in Visual Basic, 18432 bytes in size.
Installation
The worm copies itself to the Windows...
|
| 6. | P2P-Worm.Win32.Duload.b Worm.P2P.Duload represents a family of worms that replicate by copying themselves into a Kazaa network shared folder located on victim machines.
The worm itself is a Windows application (PE EXE file) written in Visual Basic, 7680 bytes in size (packed with UPX).
Installation
The worm copies...
|
| 7. | P2P-Worm.Win32.Franvir This worm spreads via file-sharing networks. The worm itself is a Windows PE EXE file approximately 1274KB in size.
Installation
Once launched, the worm causes the following error message to be displayed:
On repeated launched, the worm will cause the error message below to be displayed:
When...
|
| 8. | P2P-Worm.Win32.Gotorm This is a Worm virus. It spreads through the peer-to-peer network Kazaa. Additionally, it performs some spying functions, gathering data on certain games installed on the affected PC. This worm is a Windows application (PE EXE-file). It is written in Visual C, and its size is 196 608...
|
| 9. | P2P-Worm.Win32.Harex.c This is a peer-to-peer worm, also known as Exebat. The worm file is about 2 KB in size, packed with FSG. The unpacked file is 17 KB in size.
Installation
During installation the worm creates a folder named "sys32" in the Windows system folder and copies itself to this folder under one of the...
|
| 10. | P2P-Worm.Win32.Harex.b Harex.b (aka Genky) is about 4KB when compressed by FSG. The virus file is 33KB when uncompressed.
Installing
When installing, the worm creates a sub directory called 'windows' within the Windows directory and writes itself to this sub directory under the following names:
Ipswich Town Official...
|