Main Menu
Home
Bookmark
Contact Us



 
Win32.Oroc Viruses Information

Name: Win32.Oroc
Category: Viruses
Description: Details
Win32.Oroch

This is a non-memory resident encrypted Win32 virus. It replicates under Windows32 systems and infects PE EXE files (Windows executable) with EXE and SCR filename extensions. The virus also infects MIRC.INI files to spread its copy to mIRC channels, as well as infects HTML pages with a Trojan program.
The virus is quite stable and replicates with no problems except WinNT - under this system, the virus infects one of a system of EXE files that are protected by checksum. As a result, WinNT, upon booting, checks this file, reports about possible corruption and halts.
To infect PE EXE files, the virus scans Windows, Windows system and current directories, looks for .EXE and .SCR files in there, and infects them. Depending on the current time (if the current minutes are exactly 30), the virus also scans subdirectory trees on the drives from C: till H: and infects files in there.
Under WinNT and Win2000, the virus also infects MIRC.INI files and HTML pages that are found during scanning the drives. The virus overwrites HTML files with a script program that disables Internet security settings. The MIRC.INI (mIRC script file) is overwritten with a set of commands that sends the virus copy to everybody who enters the infected IRC channel.
The virus uses anti-debugging tricks in its decryption routine. It also disables several anti-virus programs:
AVP Monitor
Amon Antivirus Monitor
Norton AntiVirus
as well as deletes anti-virus data files:
ANTI-VIR.DaT, CHKLIST.DAT, CHKLIST.TAV, CHKLIST.MS, NOD32.000, AVP.CRC, IVB.NTZ, SMARTCHK.MS, SMARTCHK.CPS, KERNEL.AVC, SCAN.DAT, DEC2.DLL, AP.VIR, AP.SIG, TBSCAN.SiG
On July 3rd, the virus displays the message:
OROCHI ViRUS
AS LONG THE HUMANS RULE THE WORLDall
THE OROCHI AWAKENING IS NOT SO FAR AWAY...
IS HUMANKIND TOO LATE TO AVOID DESTRUCTION?...
WHEN THE AMBITIONS OF MANY, DRIVE THE WORLD TO THE DESTRUCTION...
TO STOP THIS, THE OROCHI EXIST...
THE OROCHI... GOD'S MESSENGER? PERHAPS...
MAY BE HUMANKIND IS AT FAULT...
HUMANKIND: AMBITIOUS, CRUEL AND RESILIENT...
BUT IT CANNOT BE FORGOTTEN... THE REAL ENEMY IS NOT OROCHI
HUMANKIND'S REAL ENEMY?
WE'VE SEEN THE ENEMY...
AND IT IS US...

The virus also has an extremely dangerous payload that is randomly activated under Win9x. This routine kills the CMOS memory and then destroys the Flash BIOS by using the same routine that was found in the Win95_CIH virus (aka Chernobyl).
The virus contains the "copyright" text strings:
ThE TimE IS HerE Th0sE Wh0 Can'T HacK ME ArE HeadeD Fr0M A L0nG SleeP
HI HackeR, HenKy LiveS HerE
OROCHI-5420 C0dE BY HenKy/[MATRiX] IN SpaiN Y2K



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Win32.Halen.259
Macro.Word.Messenge
Dementia.420
OneHalf.Madjid.293
Cascade.69
Kiev.204
PFS.378
Fingers.132
Worm.Win32.Opasoft.
I-Worm.Mimail.


 


© 2006-2008 spyware32.com - Privacy Policy