Virus Database


Win95.SGWW.2175

Description Win95.SGWW.2175

This is silly Windows95 parasitic virus. It searches for PE EXE files in the current directory and writes itself to the end of the file. While infecting a file the virus increases size of last file section, writes itself to there and modifies entry point address. The virus has bugs and may corrupt files while infecting them.
To access Windows file access functions (see the list below) the virus scans KERNEL32 exports for GetProcAddress routine and then by using this address gets addresses of other routines. This method in virus does work under Windows9x only, and does not work under Windows NT.
The virus contains the text strings:
GetProcAddress
FindFirstFileA FindNextFileA GetFileAttributesA SetFileAttributesA
CreateFileA SetFilePointer ReadFile GetFileSize CreateFileMappingA
MapViewOfFile UnmapViewOfFile CloseHandle
-=[ONE V1.0b by JFK/SGWW]=-

Check other viruses! Be aware! Use Antiviral Software

NightFall.4519

Description NightFall.4519

This is a benign memory resident polymorphic stealth parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. While installing and infecting this virus uses lot of programming tricks directed against different anti-virus utilities. The virus displays the message:
Invisible and silent - circling overland :
\ N 8 F A L L ///
Rearranged by Neurobasher - Germany
-MY-WILL-TO-DESTROY-IS-YOUR-CHANCE-FOR-IMPROVEMENTS-

NightFall.5765

Description NightFall.5765

This is a benign memory resident polymorphic stealth parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. While installing and infecting this virus uses lot of programming tricks directed against different anti-virus utilities. The virus displays the message:
"Any means necessary for survival"
_ N8FALL/2XS _
"By the perception of illusion we experience reality"
Art & Strategy by Neurobasher 1994 - Germany
"I don't think that the real violence has even started yet"
It also contains the internal text strings:
C:NCDTREENAVINOC.DAT
MIMECHSYSIMFCO
-A-VICTORY-THAT-WON'T-LAST-
Sometimes the virus launches a companion virus, that contains the texts:
C:NCDTREENAVINOC.DAT
MIMECHSYSIMFCO
-A-VICTORY-THAT-WON'T-LAST-

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



LuleÅ PlattsÄttning Ab
Ym Bil & Mekanik
StjÄrnmek HellstrÖm & Glumstrand Ab
JAN ERIKSSON SNICKERISERVICE AKTIEBOLAG
Mama Care

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com