Win95.SGWW.2175
Description Win95.SGWW.2175
This is silly Windows95 parasitic virus. It searches for PE EXE files in the current directory and writes itself to the end of the file. While infecting a file the virus increases size of last file section, writes itself to there and modifies entry point address. The virus has bugs and may corrupt files while infecting them. To access Windows file access functions (see the list below) the virus scans KERNEL32 exports for GetProcAddress routine and then by using this address gets addresses of other routines. This method in virus does work under Windows9x only, and does not work under Windows NT. The virus contains the text strings: GetProcAddress FindFirstFileA FindNextFileA GetFileAttributesA SetFileAttributesA CreateFileA SetFilePointer ReadFile GetFileSize CreateFileMappingA MapViewOfFile UnmapViewOfFile CloseHandle -=[ONE V1.0b by JFK/SGWW]=-
Check other viruses! Be aware! Use Antiviral Software
NightFall.4519
Description NightFall.4519
This is a benign memory resident polymorphic stealth parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. While installing and infecting this virus uses lot of programming tricks directed against different anti-virus utilities. The virus displays the message: Invisible and silent - circling overland : \ N 8 F A L L /// Rearranged by Neurobasher - Germany -MY-WILL-TO-DESTROY-IS-YOUR-CHANCE-FOR-IMPROVEMENTS-
NightFall.5765
Description NightFall.5765
This is a benign memory resident polymorphic stealth parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. While installing and infecting this virus uses lot of programming tricks directed against different anti-virus utilities. The virus displays the message: "Any means necessary for survival" _ N8FALL/2XS _ "By the perception of illusion we experience reality" Art & Strategy by Neurobasher 1994 - Germany "I don't think that the real violence has even started yet" It also contains the internal text strings: C:NCDTREENAVINOC.DAT MIMECHSYSIMFCO -A-VICTORY-THAT-WON'T-LAST- Sometimes the virus launches a companion virus, that contains the texts: C:NCDTREENAVINOC.DAT MIMECHSYSIMFCO -A-VICTORY-THAT-WON'T-LAST-
|