Main Menu
Home
Bookmark
Contact Us



 
Win32.Niko.517 Viruses Information

Name: Win32.Niko.517
Category: Viruses
Description: Details
Win32.Niko.5178

It is not a dangerous per-process memory resident parasitic encrypted Win32 virus. When an infected program runs, the virus decrypts its code and stays in the memory as a part of infected application. To do that the virus creates two threads: Infection and Message thread. Infection thread sleeps for some time, then scans current directory and directory threes on all drives, searches for PE EXE files and infects them. While infecting the virus writes itself to the end of last file section.
The Message thread gets the system date and on October 9th displays the MessageBox:
YOUPIIIIIIIIII
It's my birthday !!!

The Infection and Message threads can be disabled by environment strings: "NICO_VIR_OFF" string disables Infection, "NICO_VIR_CHILD_OFF" - Message thread.



Top Viruses Visited Pages:
Invader. - 234 visits
not-a-virus:RiskWare.Tool.RegPatch. - 71 visits
Worm.P2P.Harex. - 65 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 59 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 47 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Trojan.Win32.TopAntiSpyware.
Shanghai_II.407
Tiffany famil
Platov Famil
Anxiety.135
Verwolf Famil
Macro.Word.Ana
Constructor.VC
Crocodiles.159
LungHua.258


 


© 2006-2008 spyware32.com - Privacy Policy