Redtailboa.net  

Welcome to the Redtailboa.net forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, free photo gallery (10 meg upload limit), free classifieds, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact us.

Go Back   Redtailboa.net
Register FAQ Members List Calendar Arcade Search Today's Posts Mark Forums Read

» Quick Moderation
» Recent Threads
Go to first new post Pics of my Babys
Yesterday 10:50 PM
Last post by darkhelmet
Today 06:40 AM
7 Replies, 54 Views
Go to first new post a rose is a rose
Today 05:39 AM
by danktat
Last post by Xeikeness
Today 06:21 AM
5 Replies, 11 Views
Go to first new post What a day.
Today 05:40 AM
Last post by Xeikeness
Today 06:20 AM
4 Replies, 6 Views
Go to first new post Hey Everyone!
01-04-2009 07:31 AM
Last post by Jolie
Today 06:17 AM
20 Replies, 155 Views
Go to first new post Updates On The Blood!
01-05-2009 08:00 AM
Last post by Jolie
Today 06:10 AM
5 Replies, 55 Views
Go to first new post I'm A new Catahoula...
Today 05:41 AM
Last post by Stargazer
Today 06:10 AM
2 Replies, 10 Views
Go to first new post man arrested in...
Yesterday 02:37 AM
by mpgt
Last post by Jolie
Today 06:04 AM
23 Replies, 231 Views
» Ads

View Single Post
  #6 (permalink)  
Old 04-27-2002, 06:59 PM
rottie rottie is offline
Regular RTB User
 
Join Date: Jul 2001
Posts: 57
Thanks: 0
Thanked 0 Times in 0 Posts
Points: 738.19
Bank: 0.00
Total Points: 738.19
Donate
Rep Power: 18
rottie is on a distinguished road
48269

This memory-resident variant of the WORM_KLEZ.A mass-mailing worm uses SMTP to propagate via email. The subject line of the email it arrives with is randomly selected from a list of possible choices. See Tech Details for more information.

Upon execution, this worm drops files and creates an entry in the AutoRun key of the system registry. It also infects EXE files. To infect, it encrypts (compresses) the target file and then modifies the file extension with a random name. It also modifies the attributes of the file and sets these to Read-only, Hidden, System, and Archive. Thereafter, this worm copies itself to the original filename of the infected file.

This worm makes sure that its filesize is the same as that of the infected file. To do this, it pads garbage at the end of the infected file.

This worm does not perform its Antivirus Retaliation routine on machines running NT 4.0 or lower, due to an unavailability of system functions or APIs it uses to kill the antivirus-related processes



rottie
[addsig]
Add Post to del.icio.usFurl this Post!
Reply With Quote
Turbo Tax | Secured Loans | Halifax | Loans | MPAA
Powered by vBadvanced CMPS v3.0.1

All times are GMT +1. The time now is 06:46 AM.


Turbo Tax | Secured Loans | Halifax | Loans | MPAA
Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright 2000-2004 Redtailboa.net. The comments are property of their posters,
Redtailboa.net Top Herp Sites
[Output: 41.09 Kb. compressed to 39.69 Kb. by saving 1.40 Kb. (3.40%)]