Main Menu
Home
Bookmark
Contact Us



 
Wuhan.328 Viruses Information

Name: Wuhan.328
Category: Viruses
Description: Details
Wuhan.3289

It is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files (except COMMAND.COM) that are executed. The virus also scans the current directory for COM and EXE files, and infects them all. On June 24th starting from 11am the virus manifest itself in a extremely dangerous way: it reads to its memory the MBR, disk C: boot and root sectors, erases them with garbage data and displays the message:
warning!all
NO RESET
your pc had been destory by me. follow me and I can restore it for you...
you are not honest,as a punish,give you the gift...
Today is my birthday !
say HAPPY BIRTHDAY to me...

The virus then waits for the text "HAPPY BIRTHDAY" (uppercase) and restores the erased sector to their original state. Otherwise it runs some video effect which is corrupted in virus sample that was received. As a result the computer halts, and the MBR, boot and root sectors stay corrupted.
The virus also contains the text string that used as the identificator when the virus installs itself memory resident:
UNIVERSITY WUHAN



Top Viruses Visited Pages:
Invader. - 234 visits
not-a-virus:RiskWare.Tool.RegPatch. - 71 visits
Worm.P2P.Harex. - 65 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 59 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 47 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
WereWolf famil
Findme Famil
BAT.Zeke.32
Leandr
HLLP.Deftones.857
Shaware.50
Cloc
Macro.Word.Taguch
Linux.Rike.162
TheClic


 


© 2006-2008 spyware32.com - Privacy Policy