Win32.Enumiacs.6656
Description Win32.Enumiacs.6656
It is not a dangerous memory resident parasitic Windows virus. It replicates under Win32: stays in the system memory and infects PE EXE files that are run. The virus has anti-anti-virus ability: it searches for AVP Monitor window and terminates it. The virus does not manifest itself in any other way. It contains the text strings: [Enumiacs] by Virogen [NOP] Enumiacs by Virogen[NOP] ** THIS IS A BETA VERSION NOT INTENDED FOR PUBLIC RELEASE {0.5} **
When an infected file is executed, the virus gets control, scans the KERNEL32.DLL Export table and gets addresses of necessary Windows functions, and then installs itself in the Windows memory. To do that the virus creates and executes its dropper file ENUMIAC.EXE in the Windows system directory and writes its "pure" code to there. This "pure" virus dropper is an PE EXE program that has no other parts except virus code and data. When the virus dropper is executed, it stays in the Windows memory as a hidden application (service) and performs a loop of infection: the virus searches for programs that are active in the system (enumerates them), stores their names (up to 125 names), waits for some time and then infects them. While infecting the virus writes its code to the end of the file (appends to the end of last file sections) and modifies necessary PE header fields including EntryPoint address, size of image and ever recalculates file checksum.
Check other viruses! Be aware! Use Antiviral Software
Later.987
Description Later.987
This is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the beginning of COM and to the end of EXE files that are executed or opened. While installing into the memory, before return to the host program this virus disinfects the host file. If an installed DOS have version is lesser that 3.0, the virus displays on Sundays: TRANSPLANT & NETWARE
Lation.897
Description Lation.897
It is a dangerous nonmemory resident parasitic virus. It searches for .EXE files, then writes itself to the end of the file. The virus also searches for some non-EXE files and patches (corrupts?) them. The virus contains the text string: fUCKUp(C++), by <mutilation.h> 1997
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Property For Sale In Latvia Cash Advance Affiliate Properties In Malta Gravuren Durchfuehren Liebeszauber
|