Harrier.4602
Description Harrier.4602
It is not a dangerous memory resident parasitic polymorphic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. The virus infects the files with the length less than 57K, while infecting EXE files the virus converts them to COM format. The virus also encrypts a random selected block within files while infecting them. The virus does not infect the files: COMMAND.COM, IBMBIO.COM, IBMDOS.COM. While executing the programs AIDS*.*, WEB*.*, ADINF*.*, DRWEB*.* the virus terminates execution and displays one of the messages: Program too big to fit in memory Division by 0 Error in EXE file Memory allocation error! Bad command or file name Cannot load COMMAND.COM . . . Internal stack overflow! Incorrect DOS version This program requires Microsoft Windows.
While infecting a file the virus hooks INT 1, 3 (debugger) and uses these interrupts in its anti-debugging routines. The virus also hooks INT 8 (timer) and on each 256th tick checks CRC sum of its code. In case of wrong CRC sum the virus reboots the computer. While installing memory resident the virus with probability 1/8 hooks INT 17h and while printing a text replaces it with the message: Hey, Ugly User, You could be my . . . I promise You! Death to all CHAINIKS!!! Cause I am Harrier from DarkLand . . .
If a file is executed with command line starting with "@@", the virus displays the string: (c) 1996y by TechnoRat "HDL" GenNo:
followed with the number of virus generation. The virus overwrites the MBR of the hard drive with a program that depending on the system timer displays the message: I am the ¦ DARKLAND is the - - +-+ --+ --+ - --+ --+ ¦ kingdom of Hackers ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ ¦ +-¦ +-¦ +-+ +-+ ¦ +- +-+ ¦ I come from darkall ¦ ¦ ¦ ¦ ¦++ ¦++ ¦ ¦ ¦++ ¦ I invade Your PC... - - - - - - - - - --+ - - ¦ I am Your death... from DARKLAND ¦
The virus also contains the text strings: .COM.EXECOMMANDIBMBIOIBMDOSAIDSWEBADINFDRWEBALLE:WP ?VirMON-I-Virus has been installed successfully! ?VirMON-W-execution 0 error! (C)reated by HARD WISDOM!!! (hacker)
Check other viruses! Be aware! Use Antiviral Software
Gentry
Description Gentry
It is a dangerous memory resident boot virus. It hooks INT 13h and writes itself to the MBR of the hard drive and boot sectors of floppy disks. On 32nd booting the virus displays the message "AVV was here!" and halts the computer.
Geodesic.666
Description Geodesic.666
It's a harmless memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM- and EXE-files that are executed. It contains the internal text string: Geodesic Propagation v2.0
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|