Home Malware Programs Viruses Exvid

Exvid

Posted: March 28, 2006

Exvid is a virus that infects all the executable files it finds on local hard drives and accessible network shares. The spyware also attempts to spread by e-mail. Exvid sends bogus messages with malicious attachments to randomly generated e-mail addresses. Furthermore, the virus includes an integrated keylogger that records all user keystrokes and periodically sends gathered data to a predetermined e-mail account. Exvid runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 kdbdll.dll
    2 mydocument.exe
    3 mydocument[X].exe
    4 mypassword.exe
    5 mypassword[X].exe
    6 mypicture.exe
    7 mypicture[X].exe
    8 myvideo.exe
    9 myvideo[X].exe
    10 sexvideo.exe
    11 sexvideo[X].exe
    12 svchost.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunsvchostNetwareManager
Loading...