Search:       

Friday, 16 May 2008       

Win32.Maya.410 Spyware/Adware Definition


Name: Win32.Maya.410
Category: Viruses
Description: Details
Win32.Maya.4106

To get access to Windows functions the virus scans KERNEL32 export table, gets the GetProcAddress function address and then by using this value gets addresses of necessary functions:
KERNEL32.DLL:

GetModuleHandleA GetProcAddress CreateFileA WriteFile GetFileSize
CreateFileMappingA MapViewOfFile UnmapViewOfFile CloseHandle
FindFirstFileA FindNextFileA FindClose SetFilePointer SetEndOfFile
GetCurrentDirectoryA SetCurrentDirectoryA GetFileAttributesA
SetFileAttributesA GetSystemTime GetWindowsDirectoryA

USER32.DLL and ADVAPI32.DLL:

RegOpenKeyExA RegSetValueExA MessageBoxA SystemParametersInfoA

The "per-process resident" code of the virus scans current (host) process imports table and hooks following Windows file access functions, if the process imports them:
MoveFileA CopyFileA CreateFileA DeleteFileA SetFileAttributesA
GetFileAttributesA GetFullPathNameA CreateProcessA

The virus also contains the text strings:
To Aparna S. : Forever in love with youall
AYAM
IAHS
Control PanelDesktop
TileWallpaper
WallpaperStyle
SLAM.BMP


Top Viruses Visited Pages:
ECW.57
Gorgan.271
Gorill
Guerilla.199
HLLP.Nover.771
Holiday Famil
HS.90
Hydra_II Famil
I-Worm.Mimail.
I-Worm.MyLife.
I-Worm.MyLife.
I-Worm.Sobig.
Ice Famil
IDEA.612
Imi.1536.

 


Main Menu
Home
Top Downloads
New Programs
Awards
Submit
Link to us
Spyware Definitions
Viruses Info
Recipes
Jokes
Contact us



Partners
Softs Land
Hotel Reservations
Computer Articles
Viruses Info
Free Downloads
Data Recovery Shareware Downloads Free Articles
Cooks Recipes
Download Programs
Windows Drivers
MySpace Generators

Check PageRank

 

 

- Privacy Policy -