Prevent Online Threats

Win32.Bogus.409

Details
Win32.Bogus.4096

It is a silly nonmemory resident prepending Win32 virus. It gets the first .EXE file in the current directory, moves 4Kb of file header to the end of the file and overwrites file header with its own code. If the first file in directory is already infected, the virus does not infect more files. To run the host file the virus disinfects it to the temporary file with the “ZerNeboGus.exe” name. The virus does not pay attention to internal file structure, and infects DOS EXE files as well as Win32 PE EXE.
The virus contains the text strings:
Dedicated to all those who, yet, don’t understand the PE format.
Win32.ZerNeboGus (c) 1999 by the Changeling

Related Posts

  • DigiKeyGen Spyware Discovered
  • Win32.Tae
  • Win32.Bik
  • Win32.Sin
  • Win32.Mudant.88
  • Leave a Reply


    Spyware Removal Spyware Protection Tools