Virus Database


Keeper.Acid.694

Description Keeper.Acid.694

These are memory resident parasitic viruses. They hook INT 21h and write themselves to the end of the files. "Keeper.Acid.694", "Keeper.Enemy.644" and "Keeper.Eleet.726" infect EXE files that are executed, "Keeper.Massacre" infect both COM and EXE while accessing to these files.
These viruses contain the text strings:
"Keeper.Acid.694": Crypt Keeper P/S
"Keeper.Eleet.726": [ELEET] virus by Crypt Keeper
"Keeper.Enemy.644": [Enemy Within] Crypt Keeper - Phalcon/Skism
"Keeper.Lurker.546": [LURKER] Crypt Keeper
"Keeper.Massacre.742": [MIDNIGHT MASSACRE] by Crypt Keeper EXECOM
"Keeper.Massacre.775": [MIDNIGHT MASSACRE] V1.2 by Crypt Keeper EXECOM

Depending on the system time:
"Keeper.Acid.694" displays the message:
Your PC is on an [Acid Trip]all Try again later...

"Keeper.Massacre" delete the files instead of infecting them.
Keeper.China.777
It is a dangerous nonmemory resident parasitic virus. It searches for .COM files (except COMMAND.COM), then writes itself to the beginning of the file. At 1p.m. (13:00) the virus erases the disk sectors. It contains the encrypted text strings:
*.COM
COMMAND.COM
The China Syndrome Version 1.00a Written by : Crypt Keeper
Well, I guess you found the sectors... You got a warning...
This program was written in the city of Cincinnati. Non-destructive
version -A-
l8r d00d.

Keeper.Ellet.726
It also hooks INT 29h and depending on the system time replaces the symbols that are displayed by INT 29h. The symbols from the first line are replaced with the corresponding symbols from the next line:
cdegiklnostvxzCDEFGHIJKOSTUVWX
(>3G!K1N0$+V%Z[>3fgh!jk0$+uvw%

Keeper.Fly.1036, Joker.1080
These are dangerous memory resident parasitic viruses. They copy themselves to the top of the system memory, but do not correct MCB list. As a result the computer might halt. Then the viruses hook INT 21h and returns to the host program. On accessing to any file the viruses search for .COM files (except COMMAND.COM, IBMBIO.COM, IBMDOS.COM) and infect them.
"Keeper.Fly.1036":
It is encrypted virus. It writes itself to the beginning of the file. While infecting that virus encrypts the host file. Then the virus searches and overwrites the files:
SCAN.EXE CLEAN.EXE NAV.EXE CPAV.EXE TBSCAN.EXE F-PROT.EXE FLUSHOT3.COM

with the program that displays when executed:
Not enough memory.

Depending on the current time the virus displays:
[The Fly] Version 1.00 by Crypt Keeper
Be afraid... Be very afraid...

"Keeper.Joker.1080":
It writes itself to the end of the files. Depending on the system time it displays one of the messages:
You have the Joker ]I[ virus by Crypt Keeper [Joker 3]
Please insert tractor-feed toilet paper into printer
Impotence error causing erection at port adress 3E2 IRQ 5
This program requires Microsoft Windows.
Computer hungry : Insert 5-1/4 inch HAMBURGER in drive A:
Missing Light Magenta/Olive ribbon in printer.
Not enough memory.
Packed file corrupt.
Bad command or file name
Bad or missing command interpreter.

Check other viruses! Be aware! Use Antiviral Software

Beavis.655

Description Beavis.655

These are not dangerous memory resident parasitic viruses. They copy themselves into Upper Memory Blocks, hook INT 21h, then they write themselves to the end of EXE files that are executed. Depending on the system timer these viruses display one of the messages:
FIRE FIRE FIRE!
Hey butthead this sucks change the channel!
Shut up butthead or I'll kick your ass!
We're there dude.
The Beavis virus kicks ass!

The viruses also contain the text strings:
"Beavis.655,657": [BEAVIS]
"Beavis.671,673": [BEAVIS] by Crypt Keeper

Bebe.486

Description Bebe.486

These are nonresident dangerous viruses. They affect .COM-files in the current directory. They increase the size of infected file up to a paragraph, copy themselves at the file end and alter its first 14 bytes (PUSH AX; all ; JMP FAR Loc_Virus ). The viruses have an error - doesn't restore DTA. This might result in hanging up the computer. There is one more delicate error: they doesn't take into account that INTEL 80x80 processor has a conveyer, and modifies the command following the current one, the result is that the viruses work only on old IBM PC models. Apart from the above text the viruses contain the string "*.COM".
The viruses are nonresident, but they create a small memory-resident program. With this purpose they copy a part of viruses' body to the interrupt vector table at the address 0000:01CE and sets INT 1Ch or INT 21h to this program.
"Bebe.486" hooks INT 21h and while writing into file (INT 21h, f.40h) it changes '+' to '-' and '-' to '+' in buffer is writing.
"Bebe.1004" hooks INT 1Ch (timer) and some time later displays the following message:
+-------- VIRUS ! ------+
ƒ Skagi "bebe" > ƒ
+-----------------------+

After the word "bebe" is typed in from the keyboard, the virus answers: "Fig Tebe !".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com