Mpei.4772
Description Mpei.4772
This is a relatively harmless memory resident encrypted parasitic virus. It hooks INT 21h, and writes itself to the end of COM and EXE files that are executed, created or opened. The virus uses anti-debugging tricks. If Novell network is installed, the virus, depending on its counter, sends a message in Russian to all workstations in the net. On Fridays, this virus drops a program to the MBR of the hard drive that looks like a stealth boot virus, but without an infection routine, i.e., the code does all that other boot viruses do; installs itself into the memory, hooks INT 13h, and runs a stealth routine. The only exception in this code is that it does not contain an infection routine. The virus contains the following text strings in Russian and English: COMSPEC= NAME: MPEI Windows 95 MUST DIE !!! Copyleft (c) Down'niloff Corp.,2000. All Lefts Preserved.
Check other viruses! Be aware! Use Antiviral Software
Foma family
Description Foma family
These are not dangerous memory resident parasitic viruses. They hook INT 8, 21h and write themselves to the end of COM files that are executed or opened. When the AIDSTEST anti-virus is executed, the viruses display one the messages and halt the system: Abnormal program termination ?KMON-F-System read failure halt 177640 Unrecognised error. DMA failure.
Depending on the system date and their counters the virus blink the screen or display messages in Russian. The viruses also contain the text strings: "Foma.972": STIN V:1.02 "Foma.1000": STIN V:1.01 "Foma.1200": STIN V:1.00 ( CGA/EGA/VGA Terminal Color Invertor ) 11-Nov-1991. Kpy ¼ «p á½ ¡¿ á¼ ¿ ¡Ñ ½áí ¼ ¿ «ó¿ á¼ »« ó áÑ all..... "Foma.1733": FOMA V:1.01 "Foma.1900": FOMA V:1.00
Foo.956
Description Foo.956
It is not a dangerous nonmemory resident encrypted parasitic virus. It searches for COM files in current and in parent directories, then in C:WINDOWS directory and infects not more than three files found. While infecting the virus writes itself to the end of the file. The virus pays attention to the internal self-checking Windows32 ability and fix the necessary date ("ENUNS" field at the end of Windows COM files) while infecting them. The virus uses anti-debugging tricks. On 29th of any month it displays the message and halts the computer: --FOO VIRUS-- WE'RE ALL STARS NOW, IN THE DOPESHOW MADE IN THE UK, WE EXIST..
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Ecommerce Wordpress Themes Chicago Storage Units Airtech Energy Sweden Kommanditbolag Borg, Johnny Bergs StÄd Och FÖnsterputs
|