Win32.Dream.4916
Description Win32.Dream.4916
This is a relatively harmless per-process memory resident parasitic polymorphic Win32 virus. It stays as a thread of the host process and infects Windows EXE and Help files that are accessed. To intercept files accessed, the virus hooks the "CreateFileA" Windows function. While infecting EXE and HLP files, the virus writes itself to the end of the file and modifies the necessary file-structure fields. To run as a Windows application from HLP files, the virus uses a trick that for the first time was used by the "WinHLP.Demo" virus. The virus has bugs, and infected files in some cases are damaged by the virus. Upon being activated, they cause a standard Windows message to appear about an error in application. The virus contains the following text strings: Win32.Dream, (c)oded by Prizzy/29A The greetz go to all 29A vx coderz
Check other viruses! Be aware! Use Antiviral Software
MegaBug.546
Description MegaBug.546
It is a dangerous memory resident parasitic encrypted virus. It hooks INT 21h and writes itself to the end of .COM files that are executed. On 28th of any month it erases the disk sectors. It contains the text string: V.C.M-MEGABUG
MegaDevil.665
Description MegaDevil.665
It is a dangerous memory resident parasitic virus. It hooks INT 9, 21h and writes itself to the end of COM files that are executed. It copies its TSR copy to the memory at the fixed address 9000:0000 and may halt the computer because of that. On April 23th it decrypts and displays the message: Key Killer, (c) 1995 by Mega Devil in AZORES!!! - Portugal.
|