Viral Rewind: Virus.Win9x.Matrix

  Рет қаралды 302

MB Education

MB Education

10 ай бұрын

Visit my Linktree to access my socials and other channels: linktr.ee/mausolfb
-----------------------------------------------------------
. Matrix is a "harmless" memory-resident polymorphic virus for Windows 9x systems. When loaded it installs memory-resident in Windows as a VxD driver thereby providing file access and thus able to infect .EXEs and .SCRs as they're accessed (encrypting its code within the program and marking the generation of the virus). It will also infect DOS executable programs (.COM) with a text/halt payload. It will also search for any virus database files with the following names and delete them:
"AVP.CRC, ANTI-VIR.DAT, IVB.NTZ, CHKLIST.MS."
Payloads:
On the 6th of April regardless of year Matrix inserts a new registry entry within HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer of the Windows registry called "NoClose" and sets it to "1" (true). This policy prohibits Windows Explorer from allowing shutdown (removes the shutdown function from the Start Menu and from Task Manager).
On the 7th of July regardless of year when an infected DOS executable (.COM) is run the program will output the following to the screen:
"Wake up, Neo...
The Matrix has you...
w9x.mATRiX"
Afterwards it will HALT the processor which stops all activity on the machine and a hard reset/power cycle will be required.
-----------------------------
Like the Facebook page: / brian.mausolf
Follow me on Twitter: / mausolfb

Пікірлер: 2
@wadmodderschalton5763
@wadmodderschalton5763 8 ай бұрын
A worm that was capitalizing on The Matrix.
@OrangeShellGaming
@OrangeShellGaming 7 ай бұрын
The 'HALT' isn't really a halt, the virus just disables interrupts and loops forever. Since every means of getting out of the loop would involve interrupts (including e.g. Ctrl+Alt+Del which is handled as a standard interrupt internally), the loop causes the entire PC to lock up. Likewise, without interrupts, Windows cannot pre-empt processes and thus multitasking also stops working. (There could be non-maskable interrupts or NMIs that cannot be masked away by disabling interrupts, but IBM PC's don't use those for much, mostly memory parity errors.) HALT in x86 has a specific meaning: it's an instruction (HLT) that stops the CPU clock until an interrupt occurs. But why would a virus author use that, when they can just do an infinite loop...
Viral Rewind: Virus.Win9x.Chimera
13:46
MB Education
Рет қаралды 461
Virus.VBS.Sling
6:35
danooct1
Рет қаралды 70 М.
Smart Sigma Kid #funny #sigma #comedy
00:26
CRAZY GREAPA
Рет қаралды 21 МЛН
НЫСАНА КОНЦЕРТ 2024
2:26:34
Нысана театры
Рет қаралды 926 М.
Supermium - A Modern Web Browser for XP and Vista!
17:00
Michael MJD
Рет қаралды 205 М.
What is the Smallest Possible .EXE?
17:57
Inkbox
Рет қаралды 318 М.
What happens if you connect Windows XP to the Internet in 2024?
20:35
Viral Rewind: Virus.DOS.Casino
9:05
MB Education
Рет қаралды 176
Virus.Win32.Bacros
6:29
danooct1
Рет қаралды 203 М.
The Computer Bug That Almost Ended The World | The Y2k Debacle
15:53
NationSquid
Рет қаралды 2,5 МЛН
Trojan.Win32.VeryFun (Viewer-Made Malware 18)
8:46
danooct1
Рет қаралды 1 МЛН
Virus.Win32.Winfig
3:23
danooct1
Рет қаралды 360 М.
Как удвоить напряжение? #электроника #умножитель
1:00
Hi Dev! – Электроника
Рет қаралды 1,1 МЛН
1$ vs 500$ ВИРТУАЛЬНАЯ РЕАЛЬНОСТЬ !
23:20
GoldenBurst
Рет қаралды 1,9 МЛН
КРУТОЙ ТЕЛЕФОН
0:16
KINO KAIF
Рет қаралды 6 МЛН