Harpy.1219
Description Harpy.1219
These are very dangerous memory resident encrypted parasitic viruses. They hook INT 21h and write themselves to the end of .COM and .EXE files that are executed or opened. Depending on the system date the viruses corrupt files instead of infecting them, and display the messages: "Harpy.1219": Tehran`s Nights. Viruse "Harpy.1750": This is a Harpy Viruse..
Check other viruses! Be aware! Use Antiviral Software
AT.Batalia3,Batalia4
Description AT.Batalia3,Batalia4
These are harmless nonmemory resident parasitic BAT viruses. They search for BAT files in the current directory, then infect them. While infecting a file the viruses run the ARJ archiver to the pack necessary files. If there is no ARJ.EXE file in PATH, the viruses fail to replicate themselves. The viruses contain two parts of code and data. The first part (the header) contains DOS commands: "Batalia3": "Batalia4": @echo off @echo off rem YYY rem BAT4 arj x %0 -g""bÑpß >nul arj x %0 >nul ren p Int call i call i del sg ren Int a.bat del i.bat echo on @call a @echo off del i.bat del a.bat del BATalia3
The second part (the rest) is an ARJ archive. This archive contains the I.BAT file that is the main virus code and the additional files: "Batalia3": P, BATALIA3 "Batalia4": SG
The SG and BATALIA3 files contain several additional batch commands. The P file contains original code of infected BAT file (in case of "Batalia3" virus). So, any infected file contains the text strings (DOS commands) and the binary data (ARJ archive). When executed, the virus runs the ARJ archiver, extracts the files I.BAT and SG and runs I.BAT. This batch file searches for not infected BAT files in the current directory and infects them. While infecting, the "Batalia4" virus appends its code to the end of files and does not modify the original file contents. "Batalia3" saves original BAT file to ARJ archive (file P) and overwrites it. As a result the length of a file infected by "Batalia3" may be less than before infection.
Atas Family
Description Atas Family
These are non memory resident (except "Atas.1268") harmless viruses. One part of viruses body is encrypted. After getting start the viruses infect COM-files of current directory. When virus hits a file the message like "OK." or "I like to travelall" can appear on the screen. The viruses contain texts: "*.COM" and "Atas.384": ATAS(Kiev) V3.03 Cr.91.10.11 "Atas.400": ATAS V0.1 Cr.24.01.92 "Atas.1268": ATAS Corporation.(C)Copyright (B)BadWare
"Atas.1268" is the memory resident virus. If the key PrintScreen is pressed then this virus "falls" all the letters on the screen. It also hooks INT 5, 21h. Atas.3215,3233,3321 These are not dangerous memory resident encrypted stealth viruses. They hook INT 8, 10h, 16h, 1Ch, 21h and write themselves at the end of COM-files are accessed. These viruses contain the text strings: bye music letters isplay Bye-Bye. ATAS Corporation.(B)1992 ,V1 Created in the Kiev by ATAS.
These infectors check the keyboard input and compare the text entered with a words 'bye', 'music', 'letters', 'isplay'. They manifest themselves in case of word: 'music' - they play the tune; 'letters' - they 'drop' the screen letters; 'isplay' - they change the cursor position; 'bye' - they type 'Bye-Bye.' and remove the virus TSR part from the memory.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Lissabon Golfreise Acai Berry Scam Acai Berry Juice For Weight Loss Wedding Cards Golfreise
|