Virus Database


Win32.Oroch

Description Win32.Oroch

This is a non-memory resident encrypted Win32 virus. It replicates under Windows32 systems and infects PE EXE files (Windows executable) with EXE and SCR filename extensions. The virus also infects MIRC.INI files to spread its copy to mIRC channels, as well as infects HTML pages with a Trojan program.
The virus is quite stable and replicates with no problems except WinNT - under this system, the virus infects one of a system of EXE files that are protected by checksum. As a result, WinNT, upon booting, checks this file, reports about possible corruption and halts.
To infect PE EXE files, the virus scans Windows, Windows system and current directories, looks for .EXE and .SCR files in there, and infects them. Depending on the current time (if the current minutes are exactly 30), the virus also scans subdirectory trees on the drives from C: till H: and infects files in there.
Under WinNT and Win2000, the virus also infects MIRC.INI files and HTML pages that are found during scanning the drives. The virus overwrites HTML files with a script program that disables Internet security settings. The MIRC.INI (mIRC script file) is overwritten with a set of commands that sends the virus copy to everybody who enters the infected IRC channel.
The virus uses anti-debugging tricks in its decryption routine. It also disables several anti-virus programs:
AVP Monitor
Amon Antivirus Monitor
Norton AntiVirus
as well as deletes anti-virus data files:
ANTI-VIR.DaT, CHKLIST.DAT, CHKLIST.TAV, CHKLIST.MS, NOD32.000, AVP.CRC, IVB.NTZ, SMARTCHK.MS, SMARTCHK.CPS, KERNEL.AVC, SCAN.DAT, DEC2.DLL, AP.VIR, AP.SIG, TBSCAN.SiG
On July 3rd, the virus displays the message:
OROCHI ViRUS
AS LONG THE HUMANS RULE THE WORLDall
THE OROCHI AWAKENING IS NOT SO FAR AWAY...
IS HUMANKIND TOO LATE TO AVOID DESTRUCTION?...
WHEN THE AMBITIONS OF MANY, DRIVE THE WORLD TO THE DESTRUCTION...
TO STOP THIS, THE OROCHI EXIST...
THE OROCHI... GOD'S MESSENGER? PERHAPS...
MAY BE HUMANKIND IS AT FAULT...
HUMANKIND: AMBITIOUS, CRUEL AND RESILIENT...
BUT IT CANNOT BE FORGOTTEN... THE REAL ENEMY IS NOT OROCHI
HUMANKIND'S REAL ENEMY?
WE'VE SEEN THE ENEMY...
AND IT IS US...

The virus also has an extremely dangerous payload that is randomly activated under Win9x. This routine kills the CMOS memory and then destroys the Flash BIOS by using the same routine that was found in the Win95_CIH virus (aka Chernobyl).
The virus contains the "copyright" text strings:
ThE TimE IS HerE Th0sE Wh0 Can'T HacK ME ArE HeadeD Fr0M A L0nG SleeP
HI HackeR, HenKy LiveS HerE
OROCHI-5420 C0dE BY HenKy/[MATRiX] IN SpaiN Y2K

Check other viruses! Be aware! Use Antiviral Software

Pande.1520

Description Pande.1520

It is a dangerous memory resident parasitic stealth virus. It writes itself to the end of COM and EXE files that are accessed. While installing memory resident the virus scans DOS kernel, patches it, hooks INT 21h and leaves its copy in UMB memory, if it is available. If several anti-viruses (F-PROT, TBAV) or utilities (ARJ, RAR, LHA, PKZIP, CHKDISK) are run, the virus disables its stealth routines. The virus has a bug and may halt the system.
The virus contains the text strings:
pandemonium by retch
17/04/96
F-TBARRALHPKCH

Pandora

Description Pandora
It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are executed. Sometimes it displays a message in Chinese or in English:
Hello! How is it?
This is ----Pandora III.
Soochow University Business Administration Dep.
Writen By Blood Mary 1994.10.08

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Daja Akupunktur
LuleÅ HÅlmetodik Aktiebolag
Edde Competence Provider Ab
Nuek FÖrvaltnings Aktiebolag
HANTVERKARNA I NACKA AB

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com