KVS.1942
Description KVS.1942
It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. The virus does not infect file, if its name contains the letters: MM, ID or SC. On 31th the virus also hooks INT 1Ch and in some time decrypts and displays the message and halts the computer: +--------------------------------------+ ¦ ¦ ¦ Take Care of SoftWare all ¦ ¦ KieViruSoft Data Product (c) 1994 . ¦ ¦ ¦ +--------------------------------------+
The virus also contains the text: KieViruSoft (c) Ver1.0
Check other viruses! Be aware! Use Antiviral Software
Demon.348
Description Demon.348
These are harmless not memory resident parasitic viruses. They search for .COM-files of current directory and C:COMMAND.COM file and write themselves at their ends. They contain the internal text string: _=-DEMON-=_
Demon3b.4313
Description Demon3b.4313
These are dangerous memory resident stealth and polymorphic parasitic viruses. They hook INT 21h and write themselves to the end of COM and EXE files that are accessed. The viruses use quite complex stealth routine (including disinfection of the files in some cases). Demon3b.4313,4390 These are very dangerous viruses. They have several errors and may halt the system or corrupt the files while infecting them. The viruses contain the texts: "Demon3b.4313": [demon4] Hellfire "Demon3b.4390": [demon4] BETA! DONT DISTRIBUTE Hellfire
"Demon3b.4390" displays: Demon4 is Watchingall
Demon3b.4767,5670 These viruses delete anti-virus checksum files, disable tracing, avoid infection of some anti-virus programs. While accessing to write-protected disks the viruses display the message: Disk is Write Protected Please Unprotect it AND Press any key to continue . . .
The viruses contain more text strings: TBDRVXXX bc * CHKDSK.EXE ZIP.EXE ARJ.EXE SCANDISK.EXE DEFRAG.EXE SCANANTIVIRAV.AN.F-PROT.EXETBDRIVER.EXENAVTSR VSAFE.COMTBSETUP.EXETBUTIL.EXEVSHIELD.EXE [demon3b] Hellfire
|