Frodo.a
Description Frodo.a
This is a memory-resident stealth virus, 4096 (1000h) bytes long. It infects files upon execution or closing. Contamination of data-files is also possible. The virus completes its copy in such a way that the size of an infected file will grow exactly by 4096 bytes (see "Eddie.2000"). In infected files, the virus makes the time of the last modification increase by 100 years. In COM-files, it alters the first 6 bytes, and in EXE-files it alters the header. Upon entering the files, "Frodo" uses the true values of interrupt vectors 13h and 21h, which it receives using the "Yankee":algorithm. In addition to this, "Frodo" modifies the first 5 bytes of the INT 21h handler. When creating its TSR-copy, the virus occupies the top addresses that results in infecting the COMMAND.COM file. "Frodo" sets the owner address in its MCB, coinciding with the address of the first MCB owner in the system, masking it in such a way as DOS. Later, the copy of the virus might move through the memory in the direction of lower addresses, allocating new memory areas and clearing old ones. A genuine stealth virus: intercepts INT 21h, handles 20 (!) functions of it (FindFirst, FindNext, Read, Write, Lseek, Open, Create, Close, Exec etc.) and effectively masks itself. When DOS tries to access an infected file, the virus substitutes its original length and the last modification time. Upon reading or loading a file into the memory, it modifies the information read from the disk in such a way that the file appears as though it is uninfected. Upon opening an infected file for writing, the virus cures it (because writing to the file might delete part of the virus), and reinfects it upon closing. The virus runs itself from September 22nd until December 31st every year. It is not known how the virus runs itself, because the corresponding area of the virus code happens to be deleted. It may be assumed that the virus deletes the Boot-sector of a floppy-disk and the MBR-sector of the hard disk, writing its own code there. Upon rebooting from such a disk, the screen displays (using pseudo-graphic symbols) the message "FRODO LIVES!" in large letters.
Check other viruses! Be aware! Use Antiviral Software
Marzia.2048.DV
Description Marzia.2048.DV
This is a dangerous memory resident multipartite stealth virus. On execution of infected file it infects MBR of hard drive. Then it hooks INT 13h, 21h. On loading from infected sector it hooks INT 13h, waits for DOS loading and hooks INT 21h. On accessing to infected MBR (virus checks it by using INT 13h hooking) it substitutes it by not infected one. By hooking INT 21h the virus intercepts the files for infection. On installation it traces INT 13h and hooks INT 1Ch. It writes itself at the end of COM and EXE files are executed or closed. On opening of the infected file this virus cures it. It contains the internal text strings also: DVv1.00a
Marzia.2048.WW
Description Marzia.2048.WW
This is a dangerous memory resident multipartite stealth virus. On execution of infected file it infects MBR of hard drive. Then it hooks INT 13h, 21h. On loading from infected sector it hooks INT 13h, waits for DOS loading and hooks INT 21h. On accessing to infected MBR (virus checks it by using INT 13h hooking) it substitutes it by not infected one. By hooking INT 21h the virus intercepts the files for infection. On installation it traces INT 13h and hooks INT 1Ch. It writes itself at the end of COM and EXE files are executed or closed. On opening of the infected file this virus cures it. Depending on current date the virus erases the hard drive sectors or call INT 24h. On calling INT 21h, AX=3031h the virus decrypts and displays the message: Virus Development Software (c)92 PETUNIA virus Written by Willi Wonka Fago industries (c)1991 It contains the internal text strings also: MARZIA WWMARZIA
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Sms Marketing Convert Doc To Pdf Pdf Creator Truckutstyr
|