Ida.1490
Description Ida.1490
It is a dangerous memory resident parasitic polymorphic virus. It hooks INT 1Ch, 21h and writes itself to the end of COM files that are accessed. The virus polymorphic engine is quite sophisticated: the virus decryption loop does not contain decryption key "in clear" - it tries to decrypt the virus code with different keys, calculates CRC of decrypted data and passes control to the virus code if CRC is ok. This engine has a bug and in some cases the virus cannot decrypt itself and the system halts. The virus looks for the text "VERA" on the screen and appends "I Veronika !". The virus also contains the text: [IDA] v0.01 Serg_Enigma
Check other viruses! Be aware! Use Antiviral Software
Win98.Matyas
Description Win98.Matyas
This is a primitive, non-memory resident parasitic virus. It searches PE EXE files in the current directory, then writes itself to the end of the file. While spreading, the virus uses direct calls to the Windows kernel by using hardcoded addresses. These addresses are valid only in the Win98 standard edition. As a result, the virus is not able to spread under other Win32 versions. Being run under non-Win98, the virus causes a standard "error in application" message. The virus does not manifest itself in any way. It contains the text string: Màtyàs Corvinus kezdettall
04h Family
Description 04h Family
These are harmless memory resident parasitic viruses. They hook INT 21h. On DOS calls FindFirst (AH=4Eh), they search for COM files and write themselves to the beginning of the file. The viruses contain the encrypted text strings: "04h.609": 04h Virus, (c) Enrico*.com "04h.635": 04h Virus*.com
|