Virus Database


MegaDevil.665

Description MegaDevil.665

It is a dangerous memory resident parasitic virus. It hooks INT 9, 21h and writes itself to the end of COM files that are executed. It copies its TSR copy to the memory at the fixed address 9000:0000 and may halt the computer because of that. On April 23th it decrypts and displays the message:
Key Killer, (c) 1995 by Mega Devil in AZORES!!! - Portugal.

Check other viruses! Be aware! Use Antiviral Software

Mail

Description Mail

It's a not dangerous memory resident boot virus. It hooks INT 8, 9, 13h and writes itself into MBR of hard drive and floppy boot sectors. Depending on its internal counters it disables keyboard, overwrites CMOS, displays the picture:
+------------------- Help for users E-Mail ----------------------+
¦ Send/Receive Mail Manual page 137 ¦
+----------------------------------------------------------------+
¦ This command starts Commander Mail and sends any messages in ¦
¦ the OUT directory via MCI Mail. It also copies any new ¦
¦ messages from MCI Mail to the IN directory. ¦
¦ ¦
¦ Use the commander maiL command if you just want to browse ¦
¦ through messages in your IN directory, or if you want to ¦
¦ create new messages. ¦
¦ ¦
¦ Use the Send files item in the Files menu if you want to send ¦
¦ files to someone via MCI Mail. ¦
¦ ¦
¦ Note: This function is provided by the MCI.EXE and ¦
¦ MCIDRIVR.EXE programs, which must be in the same ¦
¦ directory as the Norton Commander (NC.EXE). ¦
+----------------------------------------------------------------+

Majkl Family

Description Majkl Family

These are harmless memory resident encrypted multipartite viruses. While executing of the infected file the virus writes itself to MBR of the hard drive, hooks INT 13h, 21h and then writes itself to the end of COM- and EXE-files that are executed or opened. While booting from infected MBR the virus hooks INT 8, 13h, waits for DOS loading procedure, then hooks INT 21h and hits the files.
The viruses use anti-debugger tricks bases on the features of i386+ processors. The "Majkl.1438" virus contains the text string:
Majkl

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Torsten SkÖldenklint Aktiebolag
MÄlarkvarn Inredningar Ab
PI-SA STÄD AKTIEBOLAG
GimsbÄrke Bil & Ac
LuleÅ Autolack Aktiebolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com