Virus Database


Nuker.a

Description Nuker.a

On 1st of any month it hooks INT 8,9, and slows down the computer (loop on each INT 8 call). When Alt-Ctrl-Del keys are pressed, the virus displays:
Your PC is working VERY SLOWLY todayall What about a good PENTIUM Processor ?
Before return to the host program the virus checks the system timer, and depending on its value displays the messages, waits for keystroke, compares that keystroke with random selected value, then the virus either returns to the host program, or erases the disk sectors:
+-ƒDANGER!+----------------------------------------------+
ƒ You are infected by ExCESS Virus (c) 1995 by The Nuker ƒ
ƒ--------------------------------------------------------ƒ
ƒ I have destroyed your FATs but I have only ONE copy in ƒ
ƒ my data area. IF YOU REBOOT NOW ALL DATA WILL BE LOST. ƒ
ƒ If this isn`t enough, I have altered your Master Boot ƒ
ƒ Record with a formatting routine in order to low-level ƒ
ƒ format the primary Hard Disk when executed. If you are ƒ
ƒ so dude and you don`t believe me, reboot now and look ƒ
ƒ at your hard disk light spinning... If you don`t want ƒ
ƒ to loose all your data then try to guess a number from ƒ
ƒ 0 to 9 and pray for your answer to be correct, else... ƒ
+--------------------------------------------------------+
You have 3 tries to guess the correct number!!!
Enter the number:
You fucking SHIT!!! You guessed the right number!!!
You are safe this time but next will come very soon
and you will not be so lucky!!!
Sorry, you didn`t entered the correct number!
Retry, and hope you lucky!!!
Hum... you are lucky this time...
Please wait while reconstructing disk structure...
I WAS JOKING! Your Hard Disk has been fucked up!!!
Thank you for choosing another product of...
TTThTeT TNTuTkTeTrT

Check other viruses! Be aware! Use Antiviral Software

Glue.4000.a

Description Glue.4000.a

It is a very dangerous memory resident multipartite virus. It writes itself to the end of .COM and .EXE files and to the MBR of the hard drive and boot sectors of floppy disks. The virus is encrypted in files. While accessing to infected disk sectors the virus calls its stealth routine.
When an infected file is executed, the virus hooks INT 21h and stays memory resident. It then infects the files that are executed or opened. Before infecting a file, the virus infects current disk (MBR in case of hard drive, or boot sector in case of floppy disk). While infecting a disk the virus overwrites the boot or MBR sector, then writes its code and original boot/MBR sector to the disk sectors that are then marked as bad ones. Reinfection of disks and files is possible. In some cases the virus corrupts the floppy disk boot sector while infecting. The virus also has other bugs and may halt the system while infecting a file.
On FindFirst/Next DOS calls the virus calls its stealth routine and shows decreased length of infected files. When BACKUP.COM or CHKDSK.COM utilities are run, the virus disables that routine.
While loading from infected disk the virus hooks INT 13h, waits for DOS loading process, then hooks INT 21h and INT 9 (keyboard). INT 9 handler contains a counter and increases it on any keystroke. When this counter reaches 10000, the virus starts to disable writing to disk (INT 13h) without any error message or return code. That will corrupt the files while writing to them.
The variants of this virus contain the text strings:
"Glue.4000.a":
COMEXEBACKUP.COMCHKDSK.COM
The Digital Glue (C) 1990,1991 by Eastern Digital
1900 Timi$oara
THE END

"Glue.4000.b":
COMEXEBACKUP.COMCHKDSK.COM
Lipici (C) 1991 by Eastern Digital
1900 Timi$oara

Gly.1182

Description Gly.1182

It is not a dangerous memory resident partly encrypted parasitic virus. It writes itself to the end of .COM files. When an infected file is executed, the virus infects the C:COMMAND.COM file, then hooks INT 21h and infects .COM files on DOS calls FindFirst/Next FCB (DIR command). If an infected program is executed on May 25th at 13:xx, the virus displays the message and plays a tune:
Happy birthday to you,Dear Yang !

The virus also contains the text strings:
G L Y Serial Number:

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



City Flat Anbieter
Fractional Ownership Property
American Properties
Bulgaria Property
Hungary Properties

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com