Virus Database


Win32.Champ

Description Win32.Champ

It is a dangerous nonmemory resident parasitic polymorphic Win32 virus. It infects the PE EXE files (Win32 executable). The virus infection routine has bugs and most of infected files are corrupted. They cannot be repaired and should be restored from not infected source.
On 1st of months with even numbers (February, April, June,all) the virus runs its payload routine that creates 500 garbage files with random names in three directories: Windows directory, Windows system directory and in the root directory on the drive where Windows is installed.
When infection routine is activated, the virus searches for PE EXE files in the current directory, then encrypts its body and writes to the end of the file. To get control on infected files start the virus patches the victim files' entry routine - the virus overwrites it with polymorphic code that passes control to the decryption routine in the main virus code (at the end of the file).
The virus checks file names and does not infect anti-virus programs: SCAN*, DRWE*, PAVW*, AVP3*, AVP1*, NOD3*, NOD. The virus also deletes the ANTI-VIR.DAT file, if it exists.
The virus contains the text string:
LethalMind.Champagne releaseed the 22th of March 1999.
Greetings to 29A, SLAM, Darkman, Benny, Pockets, Rod, Mist,
Thermo, Mdrg and all who have helped me. Je t'aime Laurence !

Check other viruses! Be aware! Use Antiviral Software

Gwar

Description Gwar

It is a very dangerous memory resident encrypted and stealth boot virus. It hooks INT 13h and writes itself to the boot sector of diskettes and MBR sector of hard drive that are accessed. The virus copies its TSR copy to the interrupt table. From January 1st till 7th the virus displays a message and erases sectors on the hard drive, the message looks like follows:
Gwar virus by T-2000

Gyro.512

Description Gyro.512

It is a very dangerous non memory resident encipher virus. Then the infected file is started the virus overwrites all .COM-files of current directory. The old contents of the files are not saved and not restored. After it the virus types "Bad command or file name". It also contains the texts: "*.COM", "GURO".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



FLIS O TRÄ TRANSPORT AB
HOTELL LAPONIA AB
FÄrghuset Ak Lack Ab
Fun24
Pellets

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com