Mbd.1258
Description Mbd.1258
These are not dangerous memory resident encrypted parasitic viruses. They hook INT 8, 21h and write themselves to the end of COM and EXE files that are executed. The viruses do not infect the files: DRWE*, AIDS*, AV*, ADIN*, COMM* (DRWEB, AIDSTEST, AVP, ADINF, COMMAND.COM). The virus TSR copy occupies just 232 bytes of the memory - while installing memory resident the virus saves its complete code to reserved hard drive sectors (on zero track) and reads that code from there in case of need (on infecting). The virus leaves its TSR copy (INT 8 and INT 21h handlers) in DOS data area at address 0060:0000. As a result, the virus is active, but it does not occupy conventional memory and it is not visible by any memory browser. Depending on their internal counters the viruses dial the phone number 02 (police line in Russia) or 113. The viruses contain the text string: Virus-MENT, v1.0 (C) MBD Poccuu. XI.1996 #
"Mbd.1317" has several strings in Russian, "Mbd.1258" contains they translated to English: # HELLO, POLICE ! I`M, DIRTY USER, HAVE STEAL BILLY`S WINDOWS ! # POLICE OF THE WORLD, HANDS OFF FROM CYBERSPACE !
Check other viruses! Be aware! Use Antiviral Software
Enterprise.625
Description Enterprise.625
This is a benign memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of COM-files that are executed. On December 6, it decrypts and displays the following message while halting the system: CPU error System halted
It contains the internal text string: ENTERPRISE 2
Epa.867
Description Epa.867
This is a dangerous memory resident parasitic virus. It hooks INT 1Ch and 21h, and writes itself to the end of EXE files that are opened. If the current time is 39 min 1 second, the virus decrypts and displays the strings: EPA POLLUTION PREVENTER V1.0 PRESS "POWER" KEY TO CONTINUE
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Trimning Free Cell Phones Krankenversicherung StorsjÖbygdens StÄd Ab Golf Poser
|