Win32.RainSong.3925.a
Description Win32.RainSong.3925.a
This is a dangerous per-process memory resident parasitic polymorphic Win32 virus. It searches for PE EXE files (Windows executable files) in the Windows directory and infects them. Then it stays in Windows memory as a component of the host application and infects PE EXE files that are accessed by the host application. While infecting, the virus writes itself to the end of the file by increasing the size of the last file section. The virus uses "Entry Point Obscuring" methods, and while infecting, it does not modify a program's entry address. To receive control when an infected program is run, the virus scans a victim file body, looks for a CALL command and replaces it with "JUMP VirusEntry" code. As a result, the virus gets only when the patched file code receives control, not at the beginning. The virus has a bug, and often corrupts files while infecting them. The virus avoids several anti-virus file infections, and it detects them according to the two first letters in the file name: AV*, AN*, DR*, ID*, OD*, TB*, F-* 11 months after infection, the virus halts the system. The virus code contains the text: < 99 Ways To Die Coded by Bumblebee/29a >
Check other viruses! Be aware! Use Antiviral Software
Indonga.3652
Description Indonga.3652
This virus also hooks INT 20h and 2Fh and infects COMMAND.COM as well as COM and EXE files that are accessed. On September 16, February 25, March 21, and August 27, it erases the disk sectors and displays: PINDONGA Virus V5.6. (Hecho en ARGENTINA) Programado por Otto (16977) Saludos a MAQ-MARIANO-SERGIO-ERNESTRO-COSTRA-PABLIN PD: Alguien mate a Bill Gates (El WINDOWS SE CUELGA) PINDONGA Virus (Programado por OTTO en ARGENTINA) 16977. Depending on the system conditions, "Indonga.4010" erases the hard drive sectors and displays: +-----+ |SARIN| |VIRUS| +-----+ |HECHO| | POR | |-NOP-| +-----+
Indonga.4010
Description Indonga.4010
This virus also hooks INT 20h and 2Fh and infects COMMAND.COM as well as COM and EXE files that are accessed. On September 16, February 25, March 21, and August 27, it erases the disk sectors and displays: PINDONGA Virus V5.6. (Hecho en ARGENTINA) Programado por Otto (16977) Saludos a MAQ-MARIANO-SERGIO-ERNESTRO-COSTRA-PABLIN PD: Alguien mate a Bill Gates (El WINDOWS SE CUELGA) PINDONGA Virus (Programado por OTTO en ARGENTINA) 16977. Depending on the system conditions, "Indonga.4010" erases the hard drive sectors and displays: +-----+ |SARIN| |VIRUS| +-----+ |HECHO| | POR | |-NOP-| +-----+
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
LÅssmeden I NorrkÖping Ab Tannefors Optik Ab Redakliniken Ab (specialistlÄkarna) Monikas Energy HÄlsa FÖrarbevis I Sverige Ab
|