Lifeform.2101
Description Lifeform.2101
It is a very dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are closed (i.e. the virus infects files that are copied, modified or scanned). On debugging or opening an infected file the virus disinfects it (stealth). On accessing infected files length the virus decreases it; when the F-PROT anti-virus or the ARJ, RAR, PKZIP, LHA, BACKUP utilities are run, the virus disables this stealth routine. The virus also fools the AVPLITE and F-PROT anti-virus programs. When AVPLITE is run, the virus adds the "disable heuristic scanning" to the end of command line. When F-PROT reads data from files to scan them for viruses, the virus fills data buffer with garbage. The virus also deletes the anti-virus data files: ANTI-VIR.DAT, CHKLIST.MS, SMARTCHK.CPS, AVP.CRC, IVB.NTZ, CHKLIST.TAV. Under debugger the virus corrupts the CMOS checksum field and halts the computer. On May 23th the virus erases the data on the hard drive, corrupts the CMOS and displays the message: -- [LifeForm] coded by ThE_WiZArD (1998) -- Cooler than a body on ice, Hotter than a rollin`dice Wilder than a drunken fight all You`re gonna burn tonight
The virus also contains the text strings: #ThE_WiZArD Quo vadis Fridrik? ... and you Frans still working on this shit.
Check other viruses! Be aware! Use Antiviral Software
Hanko.4167
Description Hanko.4167
It is a dangerous memory resident polymorphic and stealth parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed or closed. On opening, renaming and debugging infected files the virus disinfects them. The virus uses several levels on encryption, 64-bit key to run its random data generation routine, anti-debugging and other tricks to hide its code. On July 7th at 7:07am the virus displays the text and halts the computer: My name is Monica. I'm your new virus. If you are a programmer, you can try to decode the author's info, that is encrypted somewhere in my body. The decryption routine is also implemented. You must only guess the key all Good luck, friend. Now I stopped the computer. Press RESET, please.
There really is encrypted text in the middle of the virus code, this text is encrypted with 64-bit crypto-algorithm with unknown key. Being decrypted this text looks like follows: Hi! You are really very good. So: My name is Michal Hanko, I'm from Czech Republic. I live in Letovice, Halasova street in Southern Moravia near Brno. My E-Mail is: hanko@math.muni.cz. Please, mail me that you've been succesful. Copyright (c) Majkl soft.
Hannibal.970
Description Hannibal.970
It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the beginnings of COM files. It contains the text strings: -* DeMoRaLiZeD YoUtH *- (c) Hannibal Lechter Ni S Solu Sot Uk Ni Sakse Stain Skorin
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Aloe Vera SKANSKA GROUP PURCHASING AB VED OCH SOLTEKNIK I LÅNGSHYTTAN AB NIAN:S BENSIN & SERVICE AB Windows Freeware Download
|