FANDOM


Virus.Win9x.Atom.4790 or Atom is a non-destructive memory resident parasitic Microsoft Windows (Win9x) virus.

Behavior

When the virus is run, it displays a fake calculator program, and by using a programming trick it runs on the same level as Windows device drivers. It stays memory resident as a Windows VxD driver, hooks Windows IFS API (file access) functions, and infects PE executable files that are opened. In each infected executable, the virus creates a new file section at the end of the file named "ATOMIC99", writes its code there and modifies program's startup address.

Atom's payload activates after the computer is restarted. It drops an image of Bill Gates to the C:\ drive called "FILE.CUR". It registers this as the "arrow" state of the cursor in the Windows registry, with this key:

HKEY_USERS\.Default\Control Panel\Cursors: Arrow = C:\FILE.CUR

As one might expect, this changes the mouse cursor to a picture of Bill Gates. The virus also has the text string:

[Windows Forever,Windows Voor Altijd 199x-199x]

Aliases

Atom is also known as:

  • Win9x.Atom.4790 (Kaspersky Labs)
  • Win95.Atom.4790 (Kaspersky Labs)
  • Virus: W32/NGVCK.d.gen (McAfee)
  • W95/Atomic-4790 (Sophos)
  • W32.Atom (ClamAV)
  • W95/Atom.4790 (Panda)
  • W32/Atom.4790 (FPROT)
  • Virus:Win95/Atom.4790 (MS(OneCare))
  • Win95.Atomic.4790 (Dr. Web)
  • Win95/Atom.4790 virus (ESET NOD32)
  • Win95.Atom.4790.A (BitDef7)
  • Win95.Atom.4790 (VirusBuster)
  • Win95:Atomic (AVAST)
  • Virus.Win9x.Atom (Ikarus)
  • W95/Atom (AVG)
  • W32/Atom (Avira)
  • W95.Atom.a (NAV)
  • W32/Atom.4790 (Norman)
  • W95/Atom (NAI)
  • PE_ATOM.4790 (PCCIL)
  • Win32.Atom (Rising)
  • Virus.Win9x.Atom.4790 [AVP] (F-Secure)
  • PE_ATOM.4790 (TrendMicro)
  • Win95.Atom.4790 (VirusBusterBeta)

Videos

Virus.Win9x.Atom

Virus.Win9x.Atom.4790

Virus.Win9x.Atom.4790 by Alles


Sources

SecureList, Virus.Win9x.Atom.4790