Lazarus.2222
Description Lazarus.2222
It is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed or opened. It does not infects the COMMAND.COM and several anti-virus programs. When it is run for the first time, it infects the files, if they exist: C:DOSFORMAT.COM C:WINDOWSCOMMANDFORMAT.COM C:WIN95COMMANDFORMAT.COM
The virus deletes anti-virus data files: ANTI-VIR.DAT, CHKLIST.CPS, CHKLIST.MS, QHCHK.INF
While infecting the virus sets the writing to write-protected disk error handler (INT 24h) to incorrect address, that may crash the system. On June 2nd the virus displays a message to the center of the screen and waits for a keystroke. The message looks as follows: ++ +---+ +---+ +---+ +---+ ++ + +---+ || |+--| +---+ |+--| |+--+ || | +---+ +---+ ++ + +---+ ++ + ++ + +---+ +---+ -= LaZaRuS.2222 (c) The Shaitan/[MenACE] =-
The virus also contains the text strings: Quick Heal? HA HA HA! Interestingall Huh, Kishin F.? Greetz to all members of [MenACE]: Hitech Redneck, Cyborg, The Snake, AaronsGWC & The Shaitan!'
Check other viruses! Be aware! Use Antiviral Software
PowerPump
Description PowerPump
It is a nonmemory resident companion virus. Being executed it creates DOSPOWER.EXE files with its copy and then searches for .EXE files and creates companion .COM files. The virus writes into these .COM files the small program which executes POWER.EXE instead of original (infected) file. The virus (POWER.EXE file) searches for the files and infects them and then executes the host program. The versions of this virus contains the text strings: Null pointer assignment Divide error Abnormal program termination A:POWER.TST A:POWER.TST *.com A: A: B: B: C: C:DOS C: POWER.EXE POWER.EXE *.EXE power.exe POWER.EXE COM C:DOS POWER.EXE A:POWER.EXE C:DOSPOWER.EXE EXE
and sometimes display: "PowerPump": Power Pump v1.2 Virus - Silent But Dead. "PowerPump.b": Power Pump v1.1 - A New Kind Of Virus Power Pump v1.1 - The Choice Of A New Generation
Powertrip.423
Description Powertrip.423
It is not a dangerous memory resident parasitic virus. It hooks INT 9, 21h and writes itself to the end of COM files that are executed. It contains the text strings that is displayed on April, 25th: Jackie's on a POWERTRIP!
When Alt-Ctrl-Del keys are pressed, the virus displays: PowerTrip!
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|