Virus Database


Win16.CyberTech

Description Win16.CyberTech

It is a very dangerous memory resident parasitic virus. When an infected program is executed, the virus infects the Windows KERNEL file. When an infected KERNEL is executed, the virus hooks the WinExec function and writes itself to the end of NewEXE files that are executed.
To infect the KERNEL the virus gets the access to that file by using documented function GetModuleHandle, then the virus writes its code to the KERNEL file (KRNL286.EXE or KRNL386.EXE), and patches the system data in that file so, that the address of WinExec routine in the infected KERNEL points to the virus code. Then the virus returns the control to the host NewEXE file. So, when the infected file is executed, the virus infects only the KERNEL file.
When the system with infected KERNEL is loading, the virus stays memory resident as a part of KERNEL code, and patched WinExec address points to the virus handler. When an NewEXE file is executed, the virus infects it.
The virus separates the infected and not infected files by using the ID-label "LROY" that the virus writes to the checksum field in NewEXE header while infecting a file.
Depending on the system date and the day number the virus displays the message box bearing the title:
Chicago 7: Cyber riot

and the messages inside. The virus displays different messages, in April starting from 29th and on May 1st:
Happy anniversary, Los Angeles!
Anarchists of the world, unite!

On any Friday before the 13th of a month:
When the levee breaks, I have no place to stayall
(Crying won't help you. Praying won't do you no good.)

On March 6 and in December from 1st to 26th:
Save the Whale, harpoon a fat cat.

After displaying the message, the virus erases disk sectors.
The virus also contains the text strings:
USER KERNEL Chicago-7 CyberRiot, 15.1.1993 Klash (Werner L.)
Sommer 1993: 15 Windowscomputerviren
Coming soon: Diet riot. Same great aftertaste--fewer bytes.
Source code avaiable for $15,000,000. Serious inquiries only.
Why does IBM need to lay me off? Oh well, their loss.
McAfee's FUD equation: !!!!!!+??????=$$$$$$
Convict the pigs
This program was written in the cities of Hamburg, Chicago, Seattle and
Berkeley. Copyright (C) 1993 Klash/Skism/George J/Phalcon/Henry Buscombe
and 2 ex-Softies, collectively known as the Chicago 7.

Check other viruses! Be aware! Use Antiviral Software

Lation.897

Description Lation.897

It is a dangerous nonmemory resident parasitic virus. It searches for .EXE files, then writes itself to the end of the file. The virus also searches for some non-EXE files and patches (corrupts?) them. The virus contains the text string:
fUCKUp(C++), by <mutilation.h> 1997

Laufwerk

Description Laufwerk

It is a harmless nonmemory resident companion virus. It searches for .EXE files of the subdirectory tree of a random selected disk, renames the file that is found to the random selected name, and writes itself instead of original file.
Being executed the virus searches for the files and infects them, then it executes the host file that was renamed. This virus contains the text strings:
.exe Laufwerk:
Runtime error at .
Portions Copyright (c) 1983,90 Borland

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com