lionking.353
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
LionKing.3531
It is a dangerous memory resident stealth polymorphic parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed or closed. When an infected file is opened, the virus disinfects it. While installing and infecting the virus avoids some anti-virus programs, while executing some utilities it disables stealth routine. The virus checks the system environment and infects COMMAND.COM file. Depending on the system date the virus displays the message and erases the disk sectors:
Ja som virus Lion King
Formatujem ti disk lebo devastujes prirodu
It also contains the text strings:
Vypadni z tejto casti RAM!
TBMEMXXXTBFILXXXTBCHKXXXTBDSKXXX
VIRSCANCLEAANTICPAVGUARSHIELKITTRAPPASCSOLOTBAVMSAV
COMSPEC=
tbscan tbsetup cpav msav enav scan viverify avg nodex
pkzip arj uc lharc arc lha
chkdsk
Copyright @2006 lionking.353