Virus Database


Future.3180

Description Future.3180

It is a harmless memory resident stealth parasitic virus. On execution of infected file it scans the ENVIRONMENT area for the COMSPEC= pointer, hits the command processor (COMMAND.COM), and disinfects the host file. On execution of infected command processor the virus hooks INT 21h and writes itself to the end of COM- and EXE-files that are accessed. It contains the internal text strings:
COMSPEC=C:COMMAND.COM command.com
ARJ. .COM .com .EXE .exe AIN. ain. RAR. MSAV. C:COMMAND.COM
PATH=C:;C:NC;C:UTILS;C:RBASE_4;
Terminator Model 1.3 *Future Virus*

Check other viruses! Be aware! Use Antiviral Software

Coup.2052.a

Description Coup.2052.a

This is very dangerous memory resident multipartite virus. When an infected file is executed, the virus infects the MBR of the hard drive and then returns to DOS. While loading from infected MBR the virus cuts a block of the system memory, copies itself to there, hooks INT 13h, 1Ch and returns control to the original MBR code.
By hooking INT 13h the virus realizes a stealth routine while accessing to the infected MBR. By hooking INT 1Ch (timer) the virus waits for DOS loading process, hooks INT 21h and then writes itself to the end of .COM and .EXE files (except COMMAND.COM) that are executed. The virus checks the file names and corrupts several anti-virus scanners: SCAN, MSAV, PART*, CLEAN, VSAFE, TOOLKIT, GUARD, FINDVIRU. The virus overwrites them with a trojan program that displays the message:
Coup De Main : In Childhood taught me to Love
Now that I Love Frenzied,Said me Forget !!!

Coup.2052.b

Description Coup.2052.b

This is very dangerous memory resident multipartite virus. When an infected file is executed, the virus infects the MBR of the hard drive and then returns to DOS. While loading from infected MBR the virus cuts a block of the system memory, copies itself to there, hooks INT 13h, 1Ch and returns control to the original MBR code.
By hooking INT 13h the virus realizes a stealth routine while accessing to the infected MBR. By hooking INT 1Ch (timer) the virus waits for DOS loading process, hooks INT 21h and then writes itself to the end of .COM and .EXE files (except COMMAND.COM) that are executed. The virus checks the file names and corrupts several anti-virus scanners: SCAN, MSAV, PART*, CLEAN, VSAFE, TOOLKIT, GUARD, FINDVIRU. The virus overwrites them with a trojan program that displays the message:
If you are boy,go and play ball !!
Otherwise,Our "Blind Date" every day in "4-Bagh" at 6-9(pm).

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Avelins I Falun Aktiebolag
Roumeliotis, Georgia
Byggnadsfirma Kjell GrÖnqvist
Byggteknik Leon Ottosson
L H HÅlservice Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com