|
|
Win16.Vecna.83 Viruses Information
| Name: |
Win16.Vecna.83 |
| Category: |
Viruses |
| Description:
|
Details
Win16.Vecna.832
This is a memory resident Windows 3.xx parasitic virus. It infects NE EXE files. While infecting the virus looks for "cave" in file structure: a not used block between end of first file segment and beginning of next one. If there are 152 bytes free, the virus writes its loader to there and modifies the NE header so that this loader takes control when infected file is executed. The virus then saves its complete code to the end of the file without any changes in NE header (as an overlay code).
When an infected file is executed, the loader routine takes control. It reads virus rest code from the end of the file and leaves it in the system memory: it allocates a block of memory and hooks INT 21h by using DPMI calls. The virus then infects NE EXE files that are executed.
The virus does not manifest itself in any way, it contains the text strings:
[BONK] by Vecna/29A (c) 1998
New technology for old header formatsall |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 72 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win16.Klon.1177 - 42 visits
Win32.Hidra - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Jabb Famil
DarkParanoi
Staf.208
AWVCK.18
HelloUser Famil
Sepultura.24
Flash Famil
HMA_Boot.
Kill.57
I-Worm.Happ
|
|