Linux.Winter
Description Linux.Winter
This is a harmless non-memory resident parasitic Linux virus. It is extremely small in size for a Linux virus - just 341 bytes (in the known virus version). When an infected file is run, the virus gains control, searches for ELF files (Linux executable files) in the current directory, then writes itself to the middle of the file to the non-used "Notes section" if there is one and it has enough size. While infecting, the virus overwrites "Notes" data in the section, but the program runs properly after that. The virus contains the text string: LoTek by Wintermute The virus has a routine that sets a host name (computer name) to "Wintermute", but this routine never gains control.
Check other viruses! Be aware! Use Antiviral Software
Rasek.1490
Description Rasek.1490
This is a dangerous memory resident multipartite encrypted virus. While executing an infected file it writes itself to the MBR of the hard drive and hooks INT 13h, 12h. By hooking INT 13h this virus releases the stealth mechanism on reading the infected MBR. It also writes a trojan program to the floppy disk boot sectors. That program erases the hard drive FAT while loading from that floppy. Sometimes the virus also erases the FAT on loading from infected MBR. By hooking INT 21h the virus infects COM and EXE files that are executed, it writes itself to the end of the files. The virus contains the text string "AND.COM" and does not infect the files that contains that string in their names (COMMAND.COM). The virus also contains the text strings: RaseK v2.0,from LA CORUÑA(SPAIN).Mar93
Rasek.1492
Description Rasek.1492
This is a dangerous memory resident multipartite encrypted virus. While executing an infected file it writes itself to the MBR of the hard drive and hooks INT 13h, 12h. By hooking INT 13h this virus releases the stealth mechanism on reading the infected MBR. It also writes a trojan program to the floppy disk boot sectors. That program erases the hard drive FAT while loading from that floppy. Sometimes the virus also erases the FAT on loading from infected MBR. By hooking INT 21h the virus infects COM and EXE files that are executed, it writes itself to the end of the files. The virus contains the text string "AND.COM" and does not infect the files that contains that string in their names (COMMAND.COM). The virus also contains the text strings: "RáseK" v3.1,from La Coruña(SPAIN).Ap93
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|