Ki.962
Description Ki.962
It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the beginning of COM files that are executed. While infecting the virus searches in the file for the area that contains constant bytes, overwrites that area with the original file beginning, and then overwrites the file beginning with the virus copy. As a result the file length does not grow. This virus contains the ID-word "Ki" written backward ("iK"). It also hooks INT 1Ch (timer) and sometimes plays a tune.
Check other viruses! Be aware! Use Antiviral Software
Fantom.954
Description Fantom.954
It is a harmless memory resident multipartite virus. It writes itself to the MBR of the hard drive and to the end of EXE files. It is encrypted in files. While accessing to infected MBR the virus calls its stealth routine. When an infected file is executed, the virus infects the MBR and returns to the host program. While loading from infected MBR the virus hooks INT 8, waits for some time (to pass DOS loading process), then hooks INT 13h and INT 21h. The INT 13h handler contains only stealth routine. INT 21h handler intercepts file execution and calls infection routine. This handler also contains semi-stealth routine that is called on FindFirst/Next DOS calls. The virus contains the text string: FANTOM vir. 2.0 -(c)Szczecinek- Dla Malgorzaty P.
Faod.1433
Description Faod.1433
It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are accessed. To detect its TSR copy ("Are you here?" call) the virus uses INT 21h call with AH=FAh, the memory resident code returns AH=0Dh - this is the reason to name this virus. The virus has errors and may crash the system. On 23 and 24 of any month depending on the system time the virus displays the message in Russian (means "ASS"): XXx XX xXX xXXXXXXXXXXx XXXXXXXXXXXx xXXXXXXXXXXX xXXxXXxXXx XXx xXX XX XX XXx XX XXXXXX XX XX XX XX XXXXXXXXXXXX xXXxXXxXXx XXx xXX XX XX XXx xXX XXx XX xXX xXXXXXXXXXXx XX XX XX XX
|