Main Menu
Home
Bookmark
Contact Us



 
Win95.Vip.4309. Viruses Information

Name: Win95.Vip.4309.
Category: Viruses
Description: Details
Win95.Vip.4309.a

It is a dangerous nonmemory resident parasitic Win95 virus. It searches and infects PE EXE files in the current directory, then in Windows directory, then in root directories on C: and A: drives, and in random selected subdirectories on C: and A: drives. The virus infects up to two files in each directory on each run. While infecting the virus creates new section with ".TechnoK" name at the end of the file, and writes its code to there.
The virus checks file names and does not infect the files: WININIT.EXE, EXPLORER.EXE, DOSREP.EXE, TASKMON.EXE.
To access Windows functions to search and infect files the virus uses two sets of hard-coded addresses that are valid only under standard Win95 and Win98 editions.
On 12th of any month the virus tries to erase random selected disk sectors, but uses DOS standard of the direct write call, and as a result will definitely cause "General Protection Fault" Windows error message.
The virus contains the text strings:
ViruS "Nèmesi" by / e-ViP (electronic - Virus italian Project)



Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits

Random Viruses Pages:
Ohlala Famil
I-Worm.Runnelo
VLAD.Idle.69
Nobody.37
Sov.120
Zulu.139
Asp Famil
Macro.PPoint.Kell
Macro.Word.Ic
TrojanDownloader.Win32.Greetyah.


 


© 2006-2008 spyware32.com - Privacy Policy