Prevent Online Threats

Win32.Chop.380

Details
Win32.Chop.3808

It is not a dangerous nonmemory resident parasitic polymorphic Win32 virus. It searches for PE EXE files in the current directory, then writes itself to the end of the file.
In six month after infection affected files when run display the message box:
W32/Wm.Cocaine by Vecna/29A and Reptile/29A
Chop your breakfast in a mirror!

The virus seems to be an “alpha-version” of the “Cocaine” multi-platform Win32/Word/Email virus. The PE EXE and polymorphic engines in the “Chop” virus are very closed to “Cocaine” routines, and there are several empty (do-nothing) routines in the “Chop” that are functional in the “Cocaine”.

Related Posts

  • Win32.Tae
  • Win32.Bik
  • Win32.Sin
  • Win32.Mudant.88
  • Win32.Seppuku.276
  • Leave a Reply


    Spyware Removal Spyware Protection Tools