Selected viruses, spyware, and other threats: sorted alphabetically
Short description
Win32/Drowor.A is a file infector. Installation
When executed, the virus copies itself into the: - %windir%\system\
- internat.exe (30001 B)
- internat.exe.tmp (30001 B)
- _.de (30001 B)
Executable files infection
The virus searches local and network drives for files with one of the following extensions: - .exe
The host file is modified in a way that causes the virus to be executed prior to running the original code. Size of the code inserted is 30986 B .
It avoids files which contain any of the following strings in their path:
- System Volume Information
- Recycled
- KartRider.exe
- NMService.exe
- patchupdate.exe
- ztconfig.exe
- wool.exe
Spreading
The virus copies itself into the root folders of local and remote drives. If successful the following filename is used:
- setup.exe
- autorun.inf
Other information
The virus creates the following files: - %windir%\win.log
The HTTP protocol is used. These are stored in the following locations:
- %windir%\system\SYSTEM32.tmp
- %windir%\system\SYSTEM32.vxd
If the virus is running in a debugger all running processes are terminated.
