deadwin.108
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
DeadWin.1088
These are memory resident encrypted parasitic stealth viruses. They hook INT 21h, and write themselves to the end of COM and EXE files that are executed or closed. When an infected file is opened, the viruses disinfect it. While infecting, the viruses can corrupt files.
The viruses check the names of files that are executed, and if the file name begins with "WI" (WIN.COM), they run their trigger routines (see below).
When WIN.COM is executed, depending on the system time (if the hours counter is equal to the seconds counter), displays the message "Dead to Windows!" and reboots the computer. It also contains the text:
Dracula lives Resucitated somewhere in time
by Dust Group, Tucumn, Argentina
On Fridays, when WIN.COM is executed, this virus checks the system timer, and if the hour counter is equal to the second counter, the virus displays the following message, and reboots the computer:
Dead to Windows!
Copyright @2006 deadwin.108