Heja.511
Description Heja.511
These are not dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of .COM files ("Heja.511" - except COMMAND.COM) that are executed. Depending on its internal counter "Heja.511" decrypts and displays the message: (c) 1993 Heja/Adrar.
"Heja.623" contains the encrypted text: >The 21th Space Explorer< ver 1.35 by HEJA from ADRAR Design. Ogladajcie nasze nowe demo - nazywa sie FUCK THE OBJECTS.
Check other viruses! Be aware! Use Antiviral Software
RZ.160
Description RZ.160
It is a dangerous memory resident parasitic virus. Being executed it copies itself into the memory at the address 6000:0000 and does not fix MCB list, that can halt the computer). Then it hooks INT 21h and writes itself to the beginning of COM files that are executed. The infected files contain the word "RZ" at their beginning.
S-Gnome.654
Description S-Gnome.654
It is not a dangerous nonmemory resident encrypted parasitic virus. It searches for .COM files, then writes itself to the end of the file. The virus deletes the anti-virus databases: CHKLIST.MS, CHKLIST.CPS. On April 1st it sets new current date: January 1st 2000. On Fridays 13th it outputs random data to the printer. At 1:30am it displays the message: REDRUM WORKING v4.4 -GK-=!AssGnomes!=- 1997
The virus also contains the text: One ring to rule them allall
|