WIN32/DONUT.A
Information about the Win32/Donut.A :
Win32/Donut is the first virus to use Microsoft's .NET.
When an infected file is executed, it searches for executable file types of .NET. It replaces the 5 Bytes stub of the file entry point and infects it by replacing it with a jump instruction. While infecting it checks for platform and infects Windows 2000 or Windows XP. It tries to infect all the .EXE files under current directory. It may copy itself repeatedly by adding a space to the filename to the existing filename.
Some times it may display a message box with the following content!.
This cell has been infected by dotNET virus!
NET.dotNET by Benny/29A
This worm first appeared on 9th January 2002.
Other names of Win32/Donut.A:
This worm is also known as Donut, W32.Donut.A.
0 Comments:
Post a Comment
<< Home