In Origine Postato da Il_Grigio
Da esegesi direi...![]()
![]()


In Origine Postato da Il_Grigio
Da esegesi direi...![]()
![]()


Virus Esegesi - Technical details
When W32.Esegesi.AA is executed, it performs the following actions:
Checks the current date. If the date is greater than September 15th 2004, 00:05, the virus write the following phrase in any post :
Da esegesi direi...![]()
OR
Creates the mutex named "aunisono", so that only one instance of the threat runs on the compromised computer.In Origine Postato da Il_Grigio
Da esegesi direi...![]()
![]()
Starts the following processes, some of which may be security-related:
ESEGESI.EXE
INCULOAGRIGIO.EXE
AFFANKULO.EXE
AUTONAITMER.EXE
LEBOWSKIFO.EXE
ANVEDI.EXE
Creates the following very hazardous files:
%Windir%\DD.exe
%Windir%\oreicalzino.exe
Note: %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.
Adds the value:
"RPCserv32g" = "%Windir%\esegesinamia.exe"
to the registry subkey:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
so that the virus runs every time Windows starts.


Bellissimo...![]()