Win32.Oroch
Description Win32.Oroch
This is a non-memory resident encrypted Win32 virus. It replicates under Windows32 systems and infects PE EXE files (Windows executable) with EXE and SCR filename extensions. The virus also infects MIRC.INI files to spread its copy to mIRC channels, as well as infects HTML pages with a Trojan program. The virus is quite stable and replicates with no problems except WinNT - under this system, the virus infects one of a system of EXE files that are protected by checksum. As a result, WinNT, upon booting, checks this file, reports about possible corruption and halts. To infect PE EXE files, the virus scans Windows, Windows system and current directories, looks for .EXE and .SCR files in there, and infects them. Depending on the current time (if the current minutes are exactly 30), the virus also scans subdirectory trees on the drives from C: till H: and infects files in there. Under WinNT and Win2000, the virus also infects MIRC.INI files and HTML pages that are found during scanning the drives. The virus overwrites HTML files with a script program that disables Internet security settings. The MIRC.INI (mIRC script file) is overwritten with a set of commands that sends the virus copy to everybody who enters the infected IRC channel. The virus uses anti-debugging tricks in its decryption routine. It also disables several anti-virus programs: AVP Monitor Amon Antivirus Monitor Norton AntiVirus as well as deletes anti-virus data files: ANTI-VIR.DaT, CHKLIST.DAT, CHKLIST.TAV, CHKLIST.MS, NOD32.000, AVP.CRC, IVB.NTZ, SMARTCHK.MS, SMARTCHK.CPS, KERNEL.AVC, SCAN.DAT, DEC2.DLL, AP.VIR, AP.SIG, TBSCAN.SiG On July 3rd, the virus displays the message: OROCHI ViRUS AS LONG THE HUMANS RULE THE WORLDall THE OROCHI AWAKENING IS NOT SO FAR AWAY... IS HUMANKIND TOO LATE TO AVOID DESTRUCTION?... WHEN THE AMBITIONS OF MANY, DRIVE THE WORLD TO THE DESTRUCTION... TO STOP THIS, THE OROCHI EXIST... THE OROCHI... GOD'S MESSENGER? PERHAPS... MAY BE HUMANKIND IS AT FAULT... HUMANKIND: AMBITIOUS, CRUEL AND RESILIENT... BUT IT CANNOT BE FORGOTTEN... THE REAL ENEMY IS NOT OROCHI HUMANKIND'S REAL ENEMY? WE'VE SEEN THE ENEMY... AND IT IS US...
The virus also has an extremely dangerous payload that is randomly activated under Win9x. This routine kills the CMOS memory and then destroys the Flash BIOS by using the same routine that was found in the Win95_CIH virus (aka Chernobyl). The virus contains the "copyright" text strings: ThE TimE IS HerE Th0sE Wh0 Can'T HacK ME ArE HeadeD Fr0M A L0nG SleeP HI HackeR, HenKy LiveS HerE OROCHI-5420 C0dE BY HenKy/[MATRiX] IN SpaiN Y2K
Check other viruses! Be aware! Use Antiviral Software
Pande.1520
Description Pande.1520
It is a dangerous memory resident parasitic stealth virus. It writes itself to the end of COM and EXE files that are accessed. While installing memory resident the virus scans DOS kernel, patches it, hooks INT 21h and leaves its copy in UMB memory, if it is available. If several anti-viruses (F-PROT, TBAV) or utilities (ARJ, RAR, LHA, PKZIP, CHKDISK) are run, the virus disables its stealth routines. The virus has a bug and may halt the system. The virus contains the text strings: pandemonium by retch 17/04/96 F-TBARRALHPKCH
Pandora
Description Pandora It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are executed. Sometimes it displays a message in Chinese or in English: Hello! How is it? This is ----Pandora III. Soochow University Business Administration Dep. Writen By Blood Mary 1994.10.08
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Daja Akupunktur LuleÅ HÅlmetodik Aktiebolag Edde Competence Provider Ab Nuek FÖrvaltnings Aktiebolag HANTVERKARNA I NACKA AB
|