Virus Database


NightFreddy.938

Description NightFreddy.938

This is a very dangerous memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of .COM files that are executed or opened. In August, it erases the MBR of the hard drive and corrupts the CMOS. The virus code contains a branch that is never summoned, and this code decrypts and displays the following message:
I'm Freddy, your nightmare

Check other viruses! Be aware! Use Antiviral Software

Dragon1

Description Dragon1

It is a very dangerous memory resident stealth boot virus. It hooks INT 13h and writes itself to the MBR of the hard drive and to the boot sector of floppy disks. The stealth procedure is buggy, and the virus may corrupt the files while reading/writing from/to infected floppy.
While infecting 12th disk the virus manifests itself by a video effect - it changes video palette. Under debugger it halts the computer.
The virus contains the text strings:
Dragon 1
(C) Snake's.
Death

DrDemon Family

Description DrDemon Family

DrDemon.1816 and 1888
These are very dangerous memory resident encrypted parasitic viruses. They trace INT 21h, hook INT 8 and 21h, and then they write themselves to the end of COM and EXE files that are accessed. The "DrDemon.1816" virus has a bug, and may corrupt files while infecting them. When the file AIDS*.* is accessed, the viruses display:
MUTABOR

The viruses display the same message in about 30 minutes after installation into the system memory.
On the 13th of any month after the 10th infection, the viruses display the following messages:
It is very long story - struggle against virusesall
(c) 1994,95 by Dr. Demon , version 4.0
Make sure all your disks are not bootable now !

and overwrite the hard drive sectors with the same strings.
DrDemon.4634
This is a harmless memory-resident polymorphic multipartite virus. While executing an infected file, the virus infects the hard-drive MBR, hooks INT 21h and stays memory resident. While loading from an infected MBR, the virus cuts 10K of DOS memory (the word at address 0000:0413), hooks INT 1Ch, waits for the DOS-loading process, hooks INT 21h and releases INT 1Ch. When any of the DOS calls Execute or Allocate, Release, Free Memory is intercepted, the virus restores the size of DOS memory, and arranges its block of memory by fixing the MCB list.
By hooking INT 21h, the virus intercepts access to COM and EXE files, and writes itself to the file end. The virus does not infect the files with the names beginning with any of the following variants:
AIDS WEB VB ADINF SCAN CLEAN DRW

The virus also contains the text string:
MB Pro (c) 1994,95 by Dr.Demon

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com