Prevent Online Threats

Lazarus.145

Details
Lazarus.1457

This is a benign memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed or opened. It does not infect the files: COMM???.*, WIN.*, F-PR??.*, VIRS???.*, TBAV.*, SCAN.*, MSAV.*, CPAV.*, CLEA?.*. On start it also infects one and following files: C:\DOS\FORMAT.COM, C:\WINDOWS\COMMAND\FORMAT.COM, C:\WIN95 COMMAND\FORMAT.COM, and deletes the files: ANTI-VIR.DAT, CHKLIST.CPS, CHKLIST.MS. When the MEM.EXE utility is run, the virus hides its block of memory. The virus contains the text string:
The Lazarus Virus (c) ‘98 The Shaitan/SLAM

Related Posts

  • Lazarus.222
  • Dutch_Tiny.Stigmat
  • Leave a Reply


    Spyware Removal Spyware Protection Tools