Virus Database


Win32.Enumiacs.6656

Description Win32.Enumiacs.6656

It is not a dangerous memory resident parasitic Windows virus. It replicates under Win32: stays in the system memory and infects PE EXE files that are run. The virus has anti-anti-virus ability: it searches for AVP Monitor window and terminates it. The virus does not manifest itself in any other way. It contains the text strings:
[Enumiacs] by Virogen [NOP]
Enumiacs by Virogen[NOP]
** THIS IS A BETA VERSION NOT INTENDED FOR PUBLIC RELEASE {0.5} **

When an infected file is executed, the virus gets control, scans the KERNEL32.DLL Export table and gets addresses of necessary Windows functions, and then installs itself in the Windows memory. To do that the virus creates and executes its dropper file ENUMIAC.EXE in the Windows system directory and writes its "pure" code to there. This "pure" virus dropper is an PE EXE program that has no other parts except virus code and data.
When the virus dropper is executed, it stays in the Windows memory as a hidden application (service) and performs a loop of infection: the virus searches for programs that are active in the system (enumerates them), stores their names (up to 125 names), waits for some time and then infects them.
While infecting the virus writes its code to the end of the file (appends to the end of last file sections) and modifies necessary PE header fields including EntryPoint address, size of image and ever recalculates file checksum.

Check other viruses! Be aware! Use Antiviral Software

Later.987

Description Later.987

This is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the beginning of COM and to the end of EXE files that are executed or opened. While installing into the memory, before return to the host program this virus disinfects the host file. If an installed DOS have version is lesser that 3.0, the virus displays on Sundays:
TRANSPLANT & NETWARE

Lation.897

Description Lation.897

It is a dangerous nonmemory resident parasitic virus. It searches for .EXE files, then writes itself to the end of the file. The virus also searches for some non-EXE files and patches (corrupts?) them. The virus contains the text string:
fUCKUp(C++), by <mutilation.h> 1997

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Property For Sale In Latvia
Cash Advance Affiliate
Properties In Malta
Gravuren Durchfuehren
Liebeszauber

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com