Virus Database


Keeper.Acid.694

Description Keeper.Acid.694

These are memory resident parasitic viruses. They hook INT 21h and write themselves to the end of the files. "Keeper.Acid.694", "Keeper.Enemy.644" and "Keeper.Eleet.726" infect EXE files that are executed, "Keeper.Massacre" infect both COM and EXE while accessing to these files.
These viruses contain the text strings:
"Keeper.Acid.694": Crypt Keeper P/S
"Keeper.Eleet.726": [ELEET] virus by Crypt Keeper
"Keeper.Enemy.644": [Enemy Within] Crypt Keeper - Phalcon/Skism
"Keeper.Lurker.546": [LURKER] Crypt Keeper
"Keeper.Massacre.742": [MIDNIGHT MASSACRE] by Crypt Keeper EXECOM
"Keeper.Massacre.775": [MIDNIGHT MASSACRE] V1.2 by Crypt Keeper EXECOM

Depending on the system time:
"Keeper.Acid.694" displays the message:
Your PC is on an [Acid Trip]all Try again later...

"Keeper.Massacre" delete the files instead of infecting them.
Keeper.China.777
It is a dangerous nonmemory resident parasitic virus. It searches for .COM files (except COMMAND.COM), then writes itself to the beginning of the file. At 1p.m. (13:00) the virus erases the disk sectors. It contains the encrypted text strings:
*.COM
COMMAND.COM
The China Syndrome Version 1.00a Written by : Crypt Keeper
Well, I guess you found the sectors... You got a warning...
This program was written in the city of Cincinnati. Non-destructive
version -A-
l8r d00d.

Keeper.Ellet.726
It also hooks INT 29h and depending on the system time replaces the symbols that are displayed by INT 29h. The symbols from the first line are replaced with the corresponding symbols from the next line:
cdegiklnostvxzCDEFGHIJKOSTUVWX
(>3G!K1N0$+V%Z[>3fgh!jk0$+uvw%

Keeper.Fly.1036, Joker.1080
These are dangerous memory resident parasitic viruses. They copy themselves to the top of the system memory, but do not correct MCB list. As a result the computer might halt. Then the viruses hook INT 21h and returns to the host program. On accessing to any file the viruses search for .COM files (except COMMAND.COM, IBMBIO.COM, IBMDOS.COM) and infect them.
"Keeper.Fly.1036":
It is encrypted virus. It writes itself to the beginning of the file. While infecting that virus encrypts the host file. Then the virus searches and overwrites the files:
SCAN.EXE CLEAN.EXE NAV.EXE CPAV.EXE TBSCAN.EXE F-PROT.EXE FLUSHOT3.COM

with the program that displays when executed:
Not enough memory.

Depending on the current time the virus displays:
[The Fly] Version 1.00 by Crypt Keeper
Be afraid... Be very afraid...

"Keeper.Joker.1080":
It writes itself to the end of the files. Depending on the system time it displays one of the messages:
You have the Joker ]I[ virus by Crypt Keeper [Joker 3]
Please insert tractor-feed toilet paper into printer
Impotence error causing erection at port adress 3E2 IRQ 5
This program requires Microsoft Windows.
Computer hungry : Insert 5-1/4 inch HAMBURGER in drive A:
Missing Light Magenta/Olive ribbon in printer.
Not enough memory.
Packed file corrupt.
Bad command or file name
Bad or missing command interpreter.

Check other viruses! Be aware! Use Antiviral Software

Epsilon Family

Description Epsilon Family

These are dangerous memory resident companion viruses. They hook INT 21h and create companion .COM files for .EXE files that are executed.
The "Epsilon.513" virus has bugs and in some cases halts the system. This virus contains the text string:
<Epsilon 1.0 (C) 15.3.1995 B.T.Pir8>

"Epsilon.1498" intercepts GetVector DOS function, and when some program gets INT 21h vector's address, the virus restores the original INT 21h address, waits for 64 keystrokes and then re-hooks INT 21h again. To do that the virus also hooks INT 16h.
This virus does not keep its complete code and data in the memory, but stores the name of the infected file. While infecting an EXE file the virus reads its complete code from that file and writes it to the companion COM file.
Depending on its random counters the virus overwrites the disk sectors with the strings:
<Epsilon 1.9 (C) 27.4.1995 B.T.Pir8 * This virus was written in the city of
Brno, Czechoslovakia (4Ever!), Europe (No such bloody America !). Drink
only Tuzemsky Rum and fuck only Slovak girls ! * A word to AEC, especially
BBS Sysop and Mrnustik & comp. : You are bloody fucked idiots ! I'l destroy
your dirty sickening BBS. Get ready, stupid idiotic lunatics ! Get ready
for WAR !!! * Message to Grisoft : Your AVG 3.3 is nice but not very
succesfull on Epsilon, I'm afraid.>

ErasePT.512

Description ErasePT.512

It is a dangerous nonmemory resident parasitic virus. It searches for EXE files in current and parent directories, then writes itself to the end of the file. The virus also writes a trojan subroutine into MBR sector. This routine erases the disk partition table after 48 thousand computer restarts.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Cégkereső

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com