Freedom Family
Description Freedom Family
These are very dangerous memory resident encrypted parasitic viruses. They hook INT 3, 21h and write themselves to the end of COM and EXE files (except COMMAND.* and AIDS*.*) that are accessed with FindFirst/Next DOS functions. The viruses also intercept Write DOS call (AH=40h), and compare the data buffer with the strings in Russian "military", "soldier", "weapon". If these strings are found, the viruses erase hard drive sectors, CMOS, and display the message: F R E E D O M
"Freedom.3600" also hooks Read functions AH=3Fh and check the data while reading as well as while writing. The viruses also contain the text strings: "Freedom.2248": COMMAND AIDS .EXE .COM * 1.45/2/01.02.1995
"Freedom.3600": COMMAND AIDS ADINF WEB .EXE .COM * 2.15/3/09.05.1995
Under debugger "Freedom.2248" corrupts the data and displays the message in the same way.
Check other viruses! Be aware! Use Antiviral Software
Elite.191
Description Elite.191
These are harmless nonmemory resident parasitic viruses of quite short length. They search for .COM files in the current directory, then write themselves to the end of the file. The viruses do not manifest themselves in any way.
Eliza.1194
Description Eliza.1194
This is a very dangerous not memory-resident overwriting virus. It searches for COM files, then writes itself to the file beginning. On Friday, 13th the virus searches for EXE files and erases their headers. Depending on the system timer this virus formats the disk sectors, and displays: ++ Hi! I am Eliza. Good Luck! ++
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|