Advent.2764
Description Advent.2764
This is non-resident harmless virus that upon execution, infects COM and EXE files. It infects EXE files in a standard way, and in COM files, it replaces the first 23h bytes in the file beginning with a jump to the virus body. The major parts of the virus are encoded. The virus don't activate if the string "VIRUS=OFF" is found in the ENVIRONMENT. From mid-November, the virus runs itself by wishing a user "MERRY CHRISTMAS!" accompanied by simple pictures and a basic musical tune.
Check other viruses! Be aware! Use Antiviral Software
Downloader.Win32.Harnig
Description Downloader.Win32.Harnig This Trojan is written in Assembler. Installation Harnig copies itself as an .exe file and a .dll file with the same random name in the Windows directory. The .exe version is registered in the system registry auto-run key as: HKLMSoftwareMicrosoftWindowsCurrentVersionRun The Trojan also creates the following file in the Windows directory: WININIT.INI Malicious effects Harnig downloads Backdoor.Afcore.aa from http//system.hoha.ru/x.pl?10 and launches it. Backdoor.Afcore.aa functions identically to Backdoor.Afcore.q
DPN.623
Description DPN.623
It is a dangerous memory resident parasitic virus. It hooks INT 1Ch, 21h and writes itself to the end of .COM-files that are executed or opened. Depending on the system timer it reboots the computer. It contains the internal text string: DPN
|