This one piece from Vecna is w9x direct action ring3 virus, need to say very tinny one. Therefore is has its limitation - uses hardcoded kernel32.dll adress, uses pretty visible signature w512 in the PE header, infects only EXE files (hard to say if this is a limitation nowadays). This one piece should be easy to understan for everyone - of you take a closer look on the source, it reasembles old DOS only times - it used vxdcalls to get onto old classic int 21h. By the way, another proof, win9x is only graphical shell extension for DOS :P

Enjoy the code !

Download source code of W512 here Download source code