Win32.Niko.5178
Description Win32.Niko.5178
It is not a dangerous per-process memory resident parasitic encrypted Win32 virus. When an infected program runs, the virus decrypts its code and stays in the memory as a part of infected application. To do that the virus creates two threads: Infection and Message thread. Infection thread sleeps for some time, then scans current directory and directory threes on all drives, searches for PE EXE files and infects them. While infecting the virus writes itself to the end of last file section. The Message thread gets the system date and on October 9th displays the MessageBox: YOUPIIIIIIIIII It's my birthday !!!
The Infection and Message threads can be disabled by environment strings: "NICO_VIR_OFF" string disables Infection, "NICO_VIR_CHILD_OFF" - Message thread.
Check other viruses! Be aware! Use Antiviral Software
Striker.461
Description Striker.461
This is a harmless nonmemory resident parasitic virus. It scans the subdirectory tree, and writes itself to the end of the .COM files. At the beginning and at the end of infected file there is the string: Striker #1
Stryke.253
Description Stryke.253
It is a harmless memory resident parasitic virus. It copies itself to the Interrupt Vectors Table, hooks INT 21h and writes itself to the end of COM files that are executed. The virus does not manifest itself in any way, it contains the text string: STRYKE
|