Hello, nice to meet you, I'm OkSpy and today we'll talk about a relatively well-known malware, but also very dangerous.
I've done such showcases in the past, so I'll start presenting them to you, I have some material, so be ready!
For those who want to see the video part of this virus, I leave you a link:
This virus has a tendency to update your Windows. If you had Windows XP, it was effectively undetectable and would have seemed like a perfectly normal update, up to 66%, where the official PayLoad* starts.
It tells us through a short "Error Box" that the Update did not find the file ntdll.dll so it will use 666.sys, which is clearly fake, and comes as an excuse for what follows, namely the continuation of the update to an eerie song, and with changed logos, followed by a loud ear-rape.
And WOW!, our PC starts, only it has small changes, very small, only the entire interface (UI) has changed.
Yes, in short, during the supposed update, the malware created a kind of Windows superimposed on the original one, and you will immediately see why.
And, in the video you will see the exact PayLoads, in short, some serious JumpScares, a creepy video (I won't give spoilers), and at the end, when you think you'll see what happens if you click on "My Computer", the virus makes a funny animation in which it "throws" your PC in the trash (here on the double 2 I really laughed out loud), and then you are assaulted by a jumpscare from the well-known FNAF 3 (Ballon Boy) and a Fake BSOD, on the red theme.
And here, the virus mechanism is briefly explained, because after that Fake BSOD, we get a real one (you can see the difference in the video), so the Virus creates an "Overlay" over the original UI (at least this is my theory, I'm waiting for your opinions below).
And at the end of the PayLoad, the MBR is rewritten so that the PC becomes Un-Bootable. Basically, the HDD is good to throw in the trash (in a way).
Dictionary:
PayLoad= Represents what the virus presents, namely the changes made to the operating system by Virus/Malware/Ransomware
UI= User-Interface, represents for example the well-known Desktop, and everything related to the appearance of an Application/Operating System, etc.
MBR= Master Boot Record, is the first sector on a hard disk that contains the boot code and the partition table.
This tells the BIOS which operating systems you have installed, which ones to boot from, which partition they are installed on, how many partitions you have, what size the partitions are and what type they are (NTFS, FAT, etc.).
If there are people who want to try the virus, they are on my Discord, but ATTENTION! Use this section only if you know what you are doing! The files there are 100% REAL viruses (Malware, Trojans, KeyLoggers, etc.) that will seriously damage your PC. USE these files only in Virtual Machines, otherwise you risk destroying your PCs. No one is responsible for the improper use of the files.