Antivirus
Network Security
Help
links
Visitor Focus
You are here:HomeAntivirus
V-Sign Virus   

Upon booting from an infected diskette, the virus makes itself memory resident in highest available 2 kByte below 640 kByte; system space is decreased by 2,048 bytes. After that, virus hooks INT 13h and modifies the boot sector image in memory by restoring the 38 bytes previously overwritten; control is then transferred to the original boot sector. On a previously not-infected hard disk, memory resident virus will infect HD partition table on first HD access; moreover, boot sectors on any not write-protected diskette accessed during memory residence of virus will be infected. The second part of the virus body is located at different places, depending on the size of the infected medium: Track: Head: Sectors: Medium: 0 0 4-5 Hard disk 0 1 2-3 5.25" DD diskette 0 1 13-14 5.25" HD diskette 0 1 4-5 3.5" DD diskette 0 1 14-15 3.5" HD diskette Upon every infection, virus increments a counter; when Counter AND Mask=0, transient damage is triggered (see below). Self-identification: After intercepting all read/write operations, virus checks for an existing infection using 9876h marker.

 
 
1260 Virus   

Program virus with direct action. It only in- fects files with COM extension. It replaces first 3 bytes with a jump to the virus.

 
June_4th Virus   

None Displayed text: "Bloody! Jun. 4 1998" June_4th ruins the BPB of floppies it infects, whichis often problematic.The virus counts the number of reboots since the harddisc was infected by incrementing a counter in the MBRand writing the MBR back to disc. If the number ofreboots is 128, 128+8, 128+16, etc, then the messageis displayed.Floppy infection is attempted on *every* Int13Read andInt13Write, causing a noticeable surfeit of floppydrive activity on infected machines.

 
Bit Addict   

The virus resides in the video RAM. The virus resides at the memory address: 0BFE2:0h Displayed text: "You have a good taste for hard disks, it was delicious !!!" Not displayed text: "BIT ADDICT" writes a bytes value 3 to port 3BFh before attempting to install itselfin memory. The int21 vector is only installed after verifying that allof the virus is successfully copied to one or the other resident address.This file is the original virus and has NOP instead of the signaturetext, so it infectable by itself once. Files smaller than 13 bytes willbe incorrectly infected because the signature text overwrites the virusstart.

 
 
Barrotes.1310.A   

Transient: Resident routine which displays a message and 8 verticalbars down the screen. The display is continually refreshedso as to be atop whatever is on the screen (80x25 textmode). The bars have a sort-of 3D effect, and theircolours (vertical stripes) are cycled by the virus. Permanent: Master Boot Record trashed

 
Barrotes   

None Displayed text: "Virus BARROTES por OSoft" (encrypted) Not displayed text: None The virus manipulates the IVT directly when hookinginterrupts. INT 21h/25h is not used.

 
Merritt Virus   

Type of Infection: Boots when infected disk is inserted and system is booted. Installs itself in high memory, removes that memory from DOS. Installs itself as the Warm-start (CTRL+ALT+DEL) interrupt handler (actually the keyboard handler); spreads by CTRL+ALT+DEL interrupt handler. Moves "real" boot sector to track 39, sector 8. Does not infect .COM or .EXE files.

 
Alabama Virus   

Damage: Permanent damage: --- Transient damage: One hour after the start of an infected program, the following message will be displayed: "SOFTWARE COPIES ARE PROHIBITED BY INTERNATIONAL LAW", "Box 1055 Tuscambia ALABAMA USA" The message is encrypted by the NOT function.

 
Akuku virus   

Type of Infection: Upon running infected file, disk must have 3000 (BB8h) bytes of free space. EXE files must be larger than 1000 (3E8h) bytes; COM files must be larger than 1000 (3E8h), but smaller than 64000 (FA00h) bytes.

 
Satan Virus   

Easy identification: text visible in bootblock: "Dark is the night, and so is your mind!" "You are now possessed by the SATAN virus!" "Dial 22304940, and ask for the EXORCIST!" ""Dominique et spiritus et sanctus"" "Long live the anti-christ, and please don't" "forget to turn the lights OFF!" "Regards from The Exorcist and SATAN!"

 
 
« Start Prev 1   2   3   4   5   6   7   8   9   10   11   Next  End»