Selected viruses, spyware, and other threats: sorted alphabetically
WinNT/Infis |
This is a WIN NT kernel virus. It means that it is a resident infector. It operates only under Windows NT 4.0 with installed Service Pack 2 to 6. When an infected file is executed the virus copies itself into the file INF.SYS in the directory WinNT\System32\Drivers. Then it makes alternations in registers that result into activation of this file upon a Windows start. After activation the virus writes itself into the memory and takes over control over some of the internal system functions. It infects files in the PE format as they are opened. Upon infection it increases their length by 4608 bytes and alters the time and date in the headers to the value -1. It avoids infecting the file CMD.EXE. Because the virus contains errors it causes erroneous reports and problems in the operating system.
© 1992-2004 Eset s.r.o. All rights reserved. No part of this Encyclopedia may be reproduced, transmitted or used in any other way in any form or by any means without the prior permission.
