|
|
|
|
Win95.Lud famil Spyware/Adware Definition
| Name: |
Win95.Lud famil |
| Category: |
Viruses |
| Description:
|
Details
Win95.Lud family
This virus looks for a "cave" between first and second file sections and writes itself to there (see "Win95.CIH" virus). If there is no enough space in this cave, the virus does not infect the file. As a result of infection method, the virus does not increase the size of files while infecting them.
The virus contains the text string:
HILLARY
Lud.Jez
This virus infects the files by using one of standard ways: it creates new section at the end of the file and writes itself to there. This section is named ".jezzy". The virus also contains the text:
The Jezebel Virus
Lud.Jadis, Lud.Yel
These viruses use more sophisticated method: while infecting a file they scan it for executable section, move all other sections down to allocate a "cave" of necessary size, write themselves to there and fix parameters of all modified sections: size, offset in file, e.t.c. The viruses also pay special attention for sections that contain relocation tables, export and import data tables. The viruses fix all necessary fields in them.
"Lud.Jadis" also scans for PE EXE files in subdirectory tree, not only in the current directory. It contains a bug: corrupts the Import Address table. This virus contains the text string:
Your computer has eaten my turkish delight! - Jadis, Queen of Charn. |
|
Top Viruses Visited Pages:
Macro.Word.Ord
Parity.44
Pathhunt.123
Perfume Famil
Permutan.54
Phantasmagori
Pieck.201
Ply.422
PME.Burglar.326
Poem.182
Polifemo Famil
Populizer Famil
Potpis.69
Predator.115
PrintDevil.71
|
|