Golem.A - Virus for Windows by BlindWolf

Virus for Windows

Author's comments

This is my first virii, nothing special just Appender.... infect all files in the directory and all sub-directorys. Doesnt use hardcoded API adresses. Uses CRC instead of API names and keep API addresses in MMX registers. Use PEB to check if debugger present, and if debugger detected EIP cannot access memory. Use Xor encryption to encrypt the strings, the key is unique for every infected file.

