Thursday

WEIRD.10240 VIRUS

Information about the Weird.10240 virus:

Weird virus infects Executable files under Windows 95, Windows 98. This virus is a part of a remote control application, which consists of server,client and virus dropper programs. The server program carries virus. When an infected file is run under Windows 95/98 the server program will be copied to Windows folder. It will be copied as ozq-ozfds2.exe (Under Windows 95) and kzswoh.exe (Under Windows 98). It copies EXPLORER.EXE as EXPLORER.A and infects the same. It copies EXPLORER.A as EXPLORER.EXE during the next boot using WININIT.INI file. After next bootup server program hides in the memory and infects other executables.

Using any system which is running the client program, infected machine can be controlled. Using client program even the virus in the infected machine can be cleaned.

Weird.10240 virus first appeared in July 2000


Other names of Weird.10240 virus:
This virus is also known as W95/Kuang.gr.

0 Comments:

Post a Comment

<< Home