terminator.327
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
Terminator.3275
This is a benign memory resident encrypted parasitic virus. Upon being executed, it searches for CONFIG.SYS file, inserts the string "device=\vmem.sys" into that file, creates a VMEM.SYS file in the root directory of the current drive, and writes the virus dropper in the VMEM.SYS file. Then the virus returns to the host program.
While loading, DOS processes the CONFIG.SYS file and loads into the memory that infected VMEM.SYS. As a result, the virus gains control, stays memory resident as a device driver with the name "DOSxxVMS" (xx is the version of installed DOS), and hooks INT 21h. Then the virus writes itself to the end of COM and EXE files that are accessed. It does not infect the disks if there is a MICRO.BUG file in the root directory.
Depending on the current time, the virus displays the following message:
You have been stupied and careless, so now
the TERMINATOR (tm) will take over your computer.
You will get it back either when you grow up,
or get an ANTI-VIRUS.
+-------------------------------------------+
Remember: Software piracy is forbidden!
DO NOT MAKE ILLEGAL COPIES OF THIS VIRUS!!
+-------------------------------------------+
It also contains the strings:
TERMINATOR
COMSPEC=
\micro.bug
device=\vmem.sys
A:\config.sys
A:\msdos.*
A:\ibmdos.*
A:\command.*
Copyright @2006 terminator.327