Dette kunne også være en mulighed
When the virus is executed it first checks the date. If the date is September 11 of any year, on Windows 2000 computers it replaces the Bootvid.dll file with its own version. The replaced Bootvid.dll is 7 KB in size.
Bootvid.dll is a native DLL that is loaded during Windows 2000 startup to display a graphical image. In this case, if Bootvid.dll is replaced with the infected version, at startup the virus displays a 29A logo (29A is a virus writers' Web site). The virus version of Bootvid.dll is compressed inside the virus code section.
W2K.Lamchi uses a system compression library to unpack the code. This virus is a cavity infector; that is, it tries to infect .exe files that have sufficient (about 10,292 bytes) 0x90 or 0xCC bytes in the first section of Win32 executables. However, Symantec Security Response has not be able to reproduce this behavior in the virus laboratory due to apparent bugs in the virus code.
http://securityresponse.symantec.com/avcenter/venc/data/w2k.lamchi.html