Virus Database


Harpy.1219

Description Harpy.1219

These are very dangerous memory resident encrypted parasitic viruses. They hook INT 21h and write themselves to the end of .COM and .EXE files that are executed or opened. Depending on the system date the viruses corrupt files instead of infecting them, and display the messages:
"Harpy.1219": Tehran`s Nights. Viruse
"Harpy.1750": This is a Harpy Viruse..

Check other viruses! Be aware! Use Antiviral Software

AT.Batalia3,Batalia4

Description AT.Batalia3,Batalia4

These are harmless nonmemory resident parasitic BAT viruses. They search for BAT files in the current directory, then infect them. While infecting a file the viruses run the ARJ archiver to the pack necessary files. If there is no ARJ.EXE file in PATH, the viruses fail to replicate themselves.
The viruses contain two parts of code and data. The first part (the header) contains DOS commands:
"Batalia3": "Batalia4":
@echo off @echo off
rem YYY rem BAT4
arj x %0 -g""bÑpß >nul arj x %0 >nul
ren p Int call i
call i del sg
ren Int a.bat del i.bat
echo on
@call a
@echo off
del i.bat
del a.bat
del BATalia3

The second part (the rest) is an ARJ archive. This archive contains the I.BAT file that is the main virus code and the additional files:
"Batalia3": P, BATALIA3
"Batalia4": SG

The SG and BATALIA3 files contain several additional batch commands. The P file contains original code of infected BAT file (in case of "Batalia3" virus).
So, any infected file contains the text strings (DOS commands) and the binary data (ARJ archive).
When executed, the virus runs the ARJ archiver, extracts the files I.BAT and SG and runs I.BAT. This batch file searches for not infected BAT files in the current directory and infects them.
While infecting, the "Batalia4" virus appends its code to the end of files and does not modify the original file contents. "Batalia3" saves original BAT file to ARJ archive (file P) and overwrites it. As a result the length of a file infected by "Batalia3" may be less than before infection.

Atas Family

Description Atas Family

These are non memory resident (except "Atas.1268") harmless viruses. One part of viruses body is encrypted. After getting start the viruses infect COM-files of current directory. When virus hits a file the message like "OK." or "I like to travelall" can appear on the screen. The viruses contain texts: "*.COM" and
"Atas.384": ATAS(Kiev) V3.03 Cr.91.10.11
"Atas.400": ATAS V0.1 Cr.24.01.92
"Atas.1268": ATAS Corporation.(C)Copyright (B)BadWare

"Atas.1268" is the memory resident virus. If the key PrintScreen is pressed then this virus "falls" all the letters on the screen. It also hooks INT 5, 21h.
Atas.3215,3233,3321
These are not dangerous memory resident encrypted stealth viruses. They hook INT 8, 10h, 16h, 1Ch, 21h and write themselves at the end of COM-files are accessed. These viruses contain the text strings:
bye
music
letters
isplay
Bye-Bye.
ATAS Corporation.(B)1992 ,V1 Created in the Kiev by ATAS.

These infectors check the keyboard input and compare the text entered with a words 'bye', 'music', 'letters', 'isplay'. They manifest themselves in case of word: 'music' - they play the tune; 'letters' - they 'drop' the screen letters; 'isplay' - they change the cursor position; 'bye' - they type 'Bye-Bye.' and remove the virus TSR part from the memory.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Lissabon Golfreise
Acai Berry Scam
Acai Berry Juice For Weight Loss
Wedding Cards
Golfreise

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com