0 0
Dervice is not a dangerous Win32 worm virus. The virus itself is a Windows PE EXE file about 20Kb in size and written in Delphi. The virus copies itself to the Windows directory under the name "DWServise.exe", and to the A: floppy disk under the name "DW.exe". The virus spreads from floppy disks to hard drives (only in the event that a user runs the infected file on the floppy disk), and from hard drives to floppy disks. The virus also registers a copy of itself "DWServise.exe" in the system registry auto-run key:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
ServiceInternet = %WindowsDir%\DWService.exe
While spreading the virus send out 'beeps' via the PC speaker.
Device also creates the file WINSTART.BAT in the Windows directory and writes an "echo" command there that displays the following text upon Windows boot up:
You are welcomed by the manager of the disk drive of windows

Subscribe
Hot Articles