Virus Database


Gumbs.3584

Description Gumbs.3584

It is not a dangerous memory resident encrypted, stealth multipartite virus. It hooks INT 13h, 1Ch, 21h, infects the C: drive boot sector and writes itself to the end of EXE files on the floppy disks on file accessing.
When an infected file is executed, the virus writes itself to the boot sector of first drive on the hard disk (C: drive) and returns control to the host file. On rebooting the virus starts from affected boot sector, installs itself into DOS memory and hooks INT 13h and INT 21h.
By hooking INT 13h the virus hides its code presence in C: drive sectors (stealth). By hooking INT 21h the virus also runs its stealth routines, as well as infection.
On accesses to EXE files on floppy drives (A: and B:) the virus infects them. The virus does not infect the files AIDS*.EXE and DRWE*.EXE. The virus also runs its stealth routine to hide infected file length growing on floppy disks as well as on the hard drive.
On April 1st in one case of eight the virus intercepts INT 8 (timer) and plays the "Hey Jude" tune (The Beatles).
The virus contains text string in Russian and the text:
Disk I/O error.

Check other viruses! Be aware! Use Antiviral Software

Dirty.483

Description Dirty.483

It's a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM-files that are executed. On closing the file it resets its date/time stamp, but the virus contains an error and the infected files get the random date and time stamp. It contains the internal text string: "HI ! I'm The Dirty Fucker !!".

DirVirus.691

Description DirVirus.691

This is a memory-resident dangerous parasitic virus. It hooks INT 21h and infects COM files upon calling the functions FindFirst and FindNext FCB (these functions are used by the DIR command, that gave the name to the virus). The virus appends itself to the end of files, altering 6 bytes at their beginning (PUSH Loc_Virus; RET). This infector removes and does not restore the "read-only" attribute, set the file creation time to 60 sec. Sometimes it erases the FAT.
"DirVirus.760" contains the internal text strings:
COMMAND.COM
SBK (C) 1989 Varna. All rights reserved.
MANOWAR

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Kjøkkenfornyelse
Tannregulering
Arbeidsmiljøloven
Tongue Piercings
ÅSBERGS INDUSTRIRÖR AKTIEBOLAG

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com