Advent.Syslock.355
Details
Advent.Syslock.3551
This is non-resident harmless virus that upon execution, infects COM and EXE files. It infects EXE files in a standard way, and in COM files, it replaces the first 23h bytes in the file beginning with a jump to the virus body.
The major parts of the virus are encoded. The virus don’t activate if the text “SYSLOCK=@” is found in the ENVIRONMENT.
The virus replaces the string “Microsoft” with “Macrosoft” in disk sectors.
Related Posts