Virus Database


W95.Gara

Description W95.Gara

This is a dangerous Windows9x memory resident parasitic virus. It writes itself to the end of Windows executable files ("Portable Executable" - PE EXE files). When an infected program is executed, it gets control and installs itself into Windows memory: by using a trick it jumps from the application level to Windows kernel, hooks file access Windows functions (IFS API) and stays in the system memory as a VxD driver.
The virus intercepts file opening, filters PE EXE files and infects them. While infecting it increases the size of last file section, writes its code to there and modifies necessary PE header fields.
There are several virus variants known. They contains the "copyright" strings:
"Gara.842": Alpha by ULTRAS[MATRiX]
"Gara.917": [Garaipena by Billy Belcebu/DDT]
Gara.852
This virus does not manifest itself in any way.
Gara.917
This virus is dangerous one. On 31st of a month the virus tries to overwrite a block of system memory (VxD drivers area). On some system it will halt the computer, on other Windows will display an error in driver, on some of them the virus will erase video memory data.

Check other viruses! Be aware! Use Antiviral Software

Advent.Syslock.3551

Description Advent.Syslock.3551

This is non-resident harmless virus that upon execution, infects COM and EXE files. It infects EXE files in a standard way, and in COM files, it replaces the first 23h bytes in the file beginning with a jump to the virus body.
The major parts of the virus are encoded. The virus don't activate if the text "SYSLOCK=@" is found in the ENVIRONMENT.
The virus replaces the string "Microsoft" with "Macrosoft" in disk sectors.

Advert.FriendGreettings

Description Advert.FriendGreettings

Advert.FriendGreetings is an electronic post card program that once installed, unlike other similar programs, sends out emails to all addresses found in a victim computer's Microsoft address book. This obnoxious feature has lead some anti-virus companies to classify this program as a "worm".
If a user clicks on the link found in the email the installation procedure begins.
During installation the program displays a certificate of authenticity. If a user accepts the electronic signature he or she is given the chance to look over a license agreement (EULA). tIf a user either disagrees with the license agreement or doesn't trust the certificate, installation of the program terminates.
The Certificate verifying "safe content"!

When a user accepts the license agreement (below picture)the program is installed on their machine and "Advert.FriendGreetings" proceeds to send out messages to all the addresses found in their Microsoft Outlook address book.
The License Agreement

The email messages look as follows:
Subject: %recipient% you have an E-Card from %sender%.
Message:
Greetings!

%sender% has sent you an E-Card -- a virtual postcard from FriendGreetings.com. You can pickup your E-Card at the FriendGreetings.com by clicking on the link below.

http:/ /www.friendgreetings.com/pickup/pickup.aspx?
Message:
------------------------------------------------------------
%recipient%M
I sent you a greeting card. Please pick it up.
%sender%
------------------------------------------------------------

When this software installs it adds the following registry keys:

[HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun]
"PMedia"="C:Program FilesCommon FilesMediawinsrvc.exe"

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Find A Dentist
Cheap Golf Clubs
Freelance Web Design
Proxy Website

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com