Virus Database


Oeur.3072

Description Oeur.3072

This is a dangerous memory resident multipartite virus. Upon loading from an infected file, it hits the hard-drive MBR, and upon installation in a system memory, it hooks INT 13h, 21h, and F5h. Upon loading from an infected MBR, it also hooks INT 1Ch, which summons an installation routine when DOS is loaded in the system memory. Upon calling to the ChDir DOS command, the virus summons INT F5 that searches for EXE files, and writes the virus code to their ends. INT 13h is used to perform a stealth algorithm upon access to the infected MBR. In October, this virus overwrites disk sectors with data, which contains the string "oeur934" at the beginning. It contains internal text strings, and on Friday, it displays them backwards:
$?! ynnuf uoy erA
$.akrakurD all eis im izduN
$.draobyeK ... em ssiK
$!!! EVITCAOIDAR si KSID DRAH ruoY
$!!! em KCUF ton oD
$:A evird otni AZZIP tresnI ! yrgnuh ma J
$setteksid owt era :A evird nI ! gninraW
$$ejeiwezdr rosecorp jowT
$emsat agaicw :C ajcats agawU
$tceted rosecorp 4XD687 oN ! gninraW
$yob diputs uoY
$.K ZSUIRAM ... .J ECZSEINGA ejukydyd asuriw ogeT
$AGA evol J
$noisrev SOD tnerrocnI
$selif erom oN
$$selif desolc ynam ooT
$noitcerder etacilpuD
$hctamsim egap edoC
$deinad sseccA
$sroloc eerhct si AGV ruoY
$ydaer ton SME
$SURIV rof yromeM etacolla tonnaC
$sretemarap KCATS dilavnI
$fys ot AGIMA
$moniks creimS
$$LUCSOK zrpeiP
$hcanalg w eizdjyzrp suzeJ
$NATAS EVA
$azorgz oT
$aselaW z zcerP
$!! corw AGA
$RAWONAM evol J
$daed si - PAR - OKSID - ONHET
$yladep ot ylap esyL
$ycicam jem do zcerp eceR
$! iwoloi
$?! ynnuf uoy erA
$.akrakurD ... eis im izduN
$.draobyeK ... em ssiK

Check other viruses! Be aware! Use Antiviral Software

HtTM.285

Description HtTM.285

These are a harmless memory resident encrypted parasitic viruses. They hook INT 21h and write themselves to the end of COM files that are executed. The viruses do not manifest themselves, they contain the text strings:
this one is unTBSCANable: die you loosy MOTHERFUCKER! [HtTM]
March '94

Hue.482

Description Hue.482

It is a harmless memory resident parasitic virus. Being executed it searches for COM files of the current directory, then writes itself to the end of the file. Then it hooks INT 21h and writes itself to the end of COM files that are executed or opened. The virus does not manifest itself in any way. It contains the text strings:
Tu Hue
*.COM I am developing !!!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com