Kaliostro family
Description Kaliostro family
These are not dangerous memory resident partly encrypted parasitic viruses. They hook INT 21h and write themselves to the end of EXE files that are executed or opened. The "Kaliostro.2098" virus also infects a file that is pointed by "MAXIMUS=" string in the system environment. "Kaliostro.2098" does not infect the files: DRWEB.EXE, ADINF.EXE, DOS4GW.EXE. The viruses also hook INT 14h (Serial Port I/O), intercept modem(?) input, wait for the "1259hackvgisnh" or "crack9db6n4mwd7" string (depending on the virus version), output via modem a message in Russian (it means "password ok") and then depending on modem input insert data into keyboard buffer: character "s", then Up or Down, then Enter. The viruses also contain the text string: òá òá òá all. I am Kaliostro 3.0 (c) Dred
Check other viruses! Be aware! Use Antiviral Software
GDIKill.1288
Description GDIKill.1288
This text was written by Alexey Podrezov, F-Secure Corp. Being run it first goes to C:WINDOWS folder. Then it checks current date and if the month is not March it passes control to original WIN.COM code. If the date is 14th of March, the virus just deletes GDI.EXE, outputs a message and passes control to original WIN.COM code. If the virus starts from a dropper (it checks 1 byte flag for that), it looks for WIN.COM file and infects it. The virus author planned that his virus would infect other COM files in case WIN.COM is already infected, but there's a bug in virus code and this doesn't happen. Also there's a routine in virus code that goes to FONTS folder and deletes all files there. But this routine is never activated.
Gdynia.680
Description Gdynia.680
Gdynia.680 is a benign non-memory resident parasitic virus. It searches for COM files, then writes itself to the end of the file. Starting from February, the virus decrypts and displays the following message: Windows 95 may be dangerous. OS/2 is the best operating system! I`ll prove it soonall
If this text is modified, the virus reboots the system. The virus also contains the text strings: *.COM * Gdynia 1996 * v1.0 *
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|