Virus Protection > computer-virus-d-page1 > - deadwin.122

deadwin.122

Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.

Description: Details
DeadWin.1228

These are memory resident encrypted parasitic stealth viruses. They hook INT 21h, and write themselves to the end of COM and EXE files that are executed or closed. When an infected file is opened, the viruses disinfect it. While infecting, the viruses can corrupt files.
The viruses check the names of files that are executed, and if the file name begins with "WI" (WIN.COM), they run their trigger routines (see below).
The virus checks the system date and time. If the system date is November 13th or June 21st, it formats the hard drive and displays the message:
hard disk destroyed!
On Fridays, when WIN.COM is executed, this virus checks the system timer, and if the hour counter is equal to the second counter, the virus displays the following message, and reboots the computer:
Dead to Windows!

Updated: 02/24/2006
Copyright @2006 deadwin.122
Webroot Software Inc.