Main Menu
Home
Bookmark
Contact Us



 
Win95.Zombie.458 Viruses Information

Name: Win95.Zombie.458
Category: Viruses
Description: Details
Win95.Zombie.4584

It is not a dangerous nonmemory resident encrypted parasitic Win95 virus. Being executed the virus scans Win95 kernel and gets undocumented addresses of system file access function (see the list below). Then it searches for NewEXE Portable Executable (Win95 and NT) files in Windows directory, in C:, D:, E: and F: drives subdirectory tree and infects them.
While infecting the virus creates new section ".Z0MBiE" in PE header, writes its code to the end of the file and modifies address of Entry Point. The virus also aligns the file length to the section, so the file lengths grows more that Virus_Length bytes while infection. The virus infect some files incorrectly, Windows displays standard error message when these files are executed.
The virus also creates ZSETUP.EXE files on disks and writes to there "Zombie.VPI" DOS virus dropper.
The virus contains the text strings, a part of these strings are the names of system functions that are used during infection:
ExitProcess FindFirstFileA FindNextFileA CreateFileA SetFilePointer
ReadFile WriteFile CloseHandle GetCurrentDirectoryA SetCurrentDirectoryA
GetWindowsDirectoryA GetCommandLineA WinExec GetFileInformationByHandle
.Z0MBiE
Z0MBiE 1.01 (c) 1997
My 2nd virii for mustdie
Tnx to S.S.R.
ZSetUp.EXE



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
TSM.553
YCHV.108
Demolited.158
RMC.155
Macro.PPoint.Attac
Press.102
TrojanDownloader.Win32.Keenval.
JFA famil
Vole Famil
Res.287


 


© 2006-2008 spyware32.com - Privacy Policy