Virus Database


Noki.448

Description Noki.448

This is a very dangerous, memory resident parasitic virus. While executing, the virus copies its code into the video memory at the address BD00:0000, and saves its code on the hard drive to sector 17 (17/0/0 - sector/track/head). Then the virus copies its INT 21h handler code (39 bytes) into Interrupt Vectors Table, hooks INT 21h, and returns control to the host file.
The virus intercepts the file execution (AX=4B00h), reads its code from hard drive sector 17 to the video memory, and jumps to there. The infection routine gains control, and infects EXE files that have the 448-bytes "cave" of zero bytes. The virus overwrites that cave, and returns from an infection routine. Thus, the file length does not grow during infection.
On the 17th of odd months (January, March,all), the virus corrupts the MBR of the hard drive. The virus contains the following text string:
NOKI

Check other viruses! Be aware! Use Antiviral Software

Candy.999

Description Candy.999

It is not a dangerous memory resident parasitic stealth virus. It hooks INT 21h and writes itself to the end of EXE files on writing to them (when files are copied or updated). The virus also has COM files infection routine, but fails to infect them because of a bug.
The virus does not manifest itself in any way. It contains the text strings:
Speak my name 5 times in front of a mirrorall
Candyman, Candyman, Candyman, Candyman, ...
Written by T-2000 / Immortal Riot

Cannabis

Description Cannabis

It's a not dangerous memory resident floppy boot-sectors infector. It hooks INT 13h. It contains the word "Cannabis". It also types:
Hey man, I don't wanna work. I'm too stoned right nowall
Non-System disk or disk error
Replace and press a key when ready

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Billigt Webbhotell
Prepaid Phone Card
Webbhotell
Matrecept
New York Fan Shop

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com