Virus Database


Heja.511

Description Heja.511

These are not dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of .COM files ("Heja.511" - except COMMAND.COM) that are executed.
Depending on its internal counter "Heja.511" decrypts and displays the message:
(c) 1993 Heja/Adrar.

"Heja.623" contains the encrypted text:
>The 21th Space Explorer< ver 1.35 by HEJA from ADRAR Design.
Ogladajcie nasze nowe demo - nazywa sie FUCK THE OBJECTS.

Check other viruses! Be aware! Use Antiviral Software

Nostardamus.3584

Description Nostardamus.3584

It is a very dangerous virus, in some cases it searches for C:*.* files and deletes them.
It uses INT 22h hook to wait the host program termination, hooks INT 21h and installs itself memory resident. It's a stealth virus, while accessing to an infected file it disinfects it. It checks the file name and do not infect several anti-virus programs.
This virus checks the file name by using the strings:
COMEXEOVLOVR
PROSCAEXTWEB
ARJRARLHAZIP
COMWINCHK
and does not infect these files or disables its stealth routines.
This virus also contains the strings:
-=Unlimited Grief=-
Kiev'96
EMME 3
Killer

Nostardamus.5995

Description Nostardamus.5995

This is a very dangerous memory resident polymorphic parasitic virus. It hooks 21h and writes itself to the end of COM and EXE files that are accessed.
Depending on the system timer and its internal counters this virus also hooks INT 10h, or INT 16h, or INT 1Ch (depending on the virus version) and manifests itself by several effects: it corrupts the files, erases the disk sectors, changes the keystrokes that are entered, displays the message:
HOME RUN !!!
The viruses also display:
The NOSTARDAMUS.Maverick (CopyLeft) Version 3.2 ultra by Populizer
Formatting disk X: 40M
It also displays about 100 stupid messages in Russian and English:
Invalid user. Unknown error !
Good user - Dead user !!!
Insert new user and press ESC
I'm big RUSSIAN monstr !!
System error, invalid TC.EXE.
See you later all
Formatting disk C: y/y ?
Press CTRL-ALT-DEL ...
Crazy & Co. ltd.
Insert new baks into drive A:
(C) Porno C++ 3.1
(C) Trubo Pascacal 7.0
Virus detected, system halted

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Outlook GMX
Algarve Car Hire
David Soard
Billiga Julklappar
MATMAGASINET I BOLLNÄS AB

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com