Havoc (Stealth_Boot) Family
Description Havoc (Stealth_Boot) Family
These are memory resident stealth boot viruses. On loading from infected floppy they write themselves into MBR of hard drive. Then they hook INT 13h and hit floppy disks on reading from them. They infect floppies by "Brain" algorithm. Depending on the system timer "Havoc.a,b" erase the disk sectors. "Havoc.Amse" is the harmless virus, it does not manifest itself. "Havoc.Alfredo" decrypts the text strings and outputs them to the printer: LIMA - PERU (c) Laboratorio Luz de Luna ANGEL X TE SALUDA
The viruses contain the internal text strings: "Havoc.a": The HAVOC Virus "Havoc.b": The Havoc ][ Virus "Havoc.Alfredo": ALFREDO "Havoc.Amse": AMSESLIFVASRORIMESAEP
Check other viruses! Be aware! Use Antiviral Software
Kemerovo.a
Description Kemerovo.a
These are dangerous nonmemory resident parasitic viruses. They search for .COM files of the current directory, then write themselves to the end of the file, and Jmp-Virus instructions (four bytes: XCHG AX,DX; JMP Loc_Virus) to the file header. Depending on the system timer these viruses might reboot the computer. They contain the string ".COM". On an attempt to infect they open the files and might left them opened.
Kernel.608
Description Kernel.608
It is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of .COM files that are executed. On June, 8th it erases the hard drive sectors and halts the computer. It contains the word "KERNEL" and encrypted string: Dedicated to tfe 13021 lost sheep. Please God, do help them.
|