Virus Database


Ghost.1447

Description Ghost.1447

It is a dangerous memory resident virus. It infects COM- and EXE-files when they are executed or opened. Before infection the infector appends to file random times of NOP (90h) instructions:
+-----------+
¦File ¦
+-----------¦
¦90h 90h all¦
+-----------¦
¦Virus ¦
+-----------+

The infector works only under DOS 3.30 because it uses some undocumented system areas and addresses of DOS 3.30: one part of the code the virus copies into one system buffer (I don't understand for why). It contains the text "MINSK GHOST,1991" and hooks INT 1Ah, 21h.

Check other viruses! Be aware! Use Antiviral Software

Ifor.1427

Description Ifor.1427

It is not a dangerous memory resident parasitic polymorphic virus. It hooks INT 21h and writes itself to the end of .EXE files that are executed. The virus deletes the anti-virus data files: ANTI-VIR.DAT, CHKLIST.MS, MSAV.CHK, AVP.CRC, CHKLIST.CPS, CHKLIST.TAV, SMARTCHK.CPS, IVB.NTZ. The virus contains the text:
[BodyCount] version POLY-B by iFOR

Ignorance

Description Ignorance

It is a harmless memory resident multipartite encrypted virus. While loading from an infected floppy disk or MBR it hooks INT 13h, waits for DOS loading and then it hooks INT 21h. While executing an infected file the virus infects the MBR of the hard drive, then hooks INT 13h and 21h. By hooking INT 13h it realizes stealth algorithm on reading the infected MBR, it also uses INT 13h for floppy boot sectors infection. By hooking INT 21h it writes itself to the end of COM, EXE and SYS files that are accessed. The virus contains the text strings:
Ignorance is Strength
Freedom is Slavery
War is Peace
COMEXEBINOVLSYSSCCLVSF-
[1984] bY [TäLöN< >NûK_] '93! THiS iZ iNFeCTi0N #00000032!
Greetz RS/NuKE!

where "#00000032" is virus generation number, that value may be not the same in different infected files/sectors. "COMEXESYSBINOVL" is the string of the file name extensions which are "infectable". "SCCLVSF-" is the string of the anti-virus software names (two bytes per name: SCAN.EXE, CLEAN.EXE, e.t.c.). While executing these files the virus disables some of its semi-stealth algorithm branches.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Free Articles Directory
Forhandler Webhotell
Grosshandel
BA E SVERIGE AB
Ferrosan Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com