Helloween

Threat description

Details

CATEGORYMalware
TYPEVirus

Summary

This virus doesn't activate, because of an mistake in code (the virus should activate on every Octomber 20th).



Removal

Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

This virus doesn't contain any destructive routine - it only tries to write the following message:

   Virus napsany specialne pro inzenyra ZAKA ze SPS      *******************      Nepodlehejte panice, mate nakazeno jen par souboru...      (c) 1993 II.A 1988      Tak a ted si vyzkousime treba: RESET      Kdyby kazdy nespokojeny student      napsal virus, tak v nasich skolach by      ani jiny software nekolov      al a McAfee by se divil...  

After this the virus waits for a keypress and then resets the machine.

The 1376 bytes long variant is nearly identical to the Helloween.1839 described above, but it displays this message:

   Nesedte porad u pocitace a zkuste jednou delat neco rozumneho!  *******************        !! Poslouchejte HELLOWEEN - nejlepsi metalovou skupinu !!  

This variant also has a different xor-coding constant, it activates on November 1st when it reboots the machine.

Submit a Sample

Suspect a file or URL was wrongly detected?
Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info