Main Menu
Home
Bookmark
Contact Us



 
Hanko.416 Viruses Information

Name: Hanko.416
Category: Viruses
Description: Details
Hanko.4167

It is a dangerous memory resident polymorphic and stealth parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed or closed. On opening, renaming and debugging infected files the virus disinfects them.
The virus uses several levels on encryption, 64-bit key to run its random data generation routine, anti-debugging and other tricks to hide its code.
On July 7th at 7:07am the virus displays the text and halts the computer:
My name is Monica. I'm your new virus. If you are a programmer,
you can try to decode the author's info, that is encrypted somewhere
in my body. The decryption routine is also implemented. You must only
guess the key all
Good luck, friend. Now I stopped the computer. Press RESET, please.

There really is encrypted text in the middle of the virus code, this text is encrypted with 64-bit crypto-algorithm with unknown key. Being decrypted this text looks like follows:
Hi! You are really very good. So: My name is Michal Hanko, I'm from
Czech Republic. I live in Letovice, Halasova street
in Southern Moravia near Brno.
My E-Mail is: hanko@math.muni.cz. Please, mail me
that you've been succesful.
Copyright (c) Majkl soft.



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
DarkElf (boot
Markus.541
Macro.Word.Buki
XEP.135
Moskau.80
BAT.Batalia
I-Worm.Cul
Beaches.109
Win.Vir_1_
Macro.Word.ShareFu


 


© 2006-2008 spyware32.com - Privacy Policy