Virus Database


Kiske.1086

Description Kiske.1086

It is not a dangerous nonmemory resident parasitic virus. It searches for .COM files, then writes itself to the end of the file. Depending on the system time the virus displays the picture:
KISKE VIRUS! XKISKE VIR
Coded AJVM! xXx Paraguay
xXXXXXXXXx x xXXXXXXXXx
xXXXXXXXXXXXXx.xXXXXXXXXXXXXx
xXXXXXXXXX xxXXXxx XXXXXXXXXXx
XXXXXXXXXXXXXXXxXXXXXXXXXXXXXXXX
XXXXXXXXXXXXXXxxxXXXXXXXXXXXXXXX
HxXXXXXXXXXXxxxxxxxXXXXXXXXXXXxH
ELLxXXXXXXXXXx xXXXXXXXXXXxELL
OWEENxxXXXXXXXXxXXXXXXXXXxxOWEEN

The virus also contains the text strings:
This virus is just for test, no lame destructor code included!
SALUDOS: ROSALBA, Lilian, Diana, Romina,
Milciades y Diego Hola INSANE (P.M.)!
¿Como andas amigazo? *.com Dark Avenger: u r the best!
Chester: eres un gran artista.
Michael Kiske: Helloween died when you went : -(
Byte Revenger: nunca cambies amigo
CBAY: I love u yet ;-)~
¡INDUSTRIA PARAGUAYA!
Añarakópe guaré Hiya Arthax (C.M.): Mandrágora rulez! :)
Escrito por Javier V.
Greetz to all PC user's arround the world.
Really, PC is the best! WINSLOWS SUXX!

Check other viruses! Be aware! Use Antiviral Software

LoveMe family

Description LoveMe family

These are not dangerous(?) memory resident encrypted parasitic viruses. They hook INT 21h and when any program is executed or current directory is changed, the viruses search for EXE files and write themselves to the end of the file. On opening some files (if full file name has "LO" characters at position 31, or "T$" at position 19) the viruses write some date (file name?) to the files:
"LoveMe.610": vol2:usr95034 love.me
"LoveMe.804": vol2:usr95225!$.$

The viruses also contain the text strings:
"LoveMe.610": (Jestem Rumburak)
"LoveMe.712": (Dr.Agon & SPERM 2.0)
"LoveMe.804": (I'm merry SPERM v2.5)

Loz Family

Description Loz Family

These are dangerous memory resident encrypted parasitic viruses. Some of them use the polymorphic technology. They hook INT 21h and write themselves to the end of COM and EXE files that are accessed (the earlier versions infect COM files only). These viruses alter the first 4 bytes of COM files (JMP Loc_Virus, DB '+'). While creating a resident copy they decrease the value of system memory (the word at 0000:0413).
"Loz.1018,1023" viruses modify system information in boot sectors of floppies (set to zero the word corresponding to the number of disk drive heads). When the AIDSTEST.EXE (soviet antiviral program) is run the viruses display: "Welcom to demo version (C) Zherkov", (thereafter in Russian) "Lozinsky - STUPID, AIDSTEST-RUBBISH" (D.Lozinsky - author of a popular Russian anti-virus program). The "Loz.1018" virus deletes the AIDSTEST.EXE program. The "Loz.1882,1915" viruses delete the AIDSTEST.EXE file as it is run and display the following message (in Russian):
+-----------------------+
¦"INVARIATRON" JV ¦
¦Antiscientific centre ¦
¦Version 5 of 11.12.90 ¦
¦Lozinsky - STUPID ¦
¦Moscow, tel. 03 ¦
+-----------------------+
The full explanation see in the next AIDSREAD.ME.

"Loz.2968" sometimes displays the following picture:
________ ___ ___ ___ ___
¦¦¦ ¦¦¦ ¦¦¦ ____ ¦¦¦ _________¦¦¦___________________¦¦¦__
¦¦¦ ¦¦¦ ___ _____¦¦¦ ________ ¦¦¦ ________ ________ ¦¦¦
¦¦¦__¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¯¯¯ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¯¯¯ ¦¦¦
¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¯¯¯¯¯¦¦¦ ¦¦¦ ¦¦¦__¦¦¦ ¯¯¯¯¯¦¦¦ ¦¦¦
¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ___ ¦¦¦ ¦¦¦ ¦¦¦
¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦__¦¦¦ ¦¦¦__¦¦¦ ¦¦¦ ¦¦¦__¦¦¦ ¦¦¦__¦¦¦ ¦¦¦
¦¦¦¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯ ¦¦¯¯¯¯¯¯¯¯¯
¦¦¦ ¦¦¦¯¦¦¦ ¦¦¦¯¦¦¦ ¦¦¦¯¯¯¯ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦ ¦¦¦¯¦¦¦
¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦¯¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦ ¦¦¦ ¦¦¦¯¦¦¦ ¦¦¦_¦¦¦
¦¦¦ ¦¦¦_¦¦¦ ¦¦¦_¦¦¦ ¦¦¦_¦¦¦ ¦¦¦_¦¦¦ ¦¦¦_¦_¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦ ¦¦¦
___________ ¦¦¦ ________________¦¦¦ _________________________

"Loz.2435" detects the virtual mode which is used by debuggers on 80x86 computers and disables debugging.
Loz.724
It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files (except COMMAND.COM) that are executed. The virus creates a counter in the MBR of the hard drive and increases it on installing into the system memory. On 100th installing the virus hooks INT 9, then it depending on pressed keys writes some data to a hard drive port. The virus contains the text string:
by ShADow Al

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Sport & Fritid I LuleÅ Ab
Payday Loan Online
GOLDEN AIR FLYG AB
Apply For A Credit Card
Gadget Geek

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com