Virus Database


Pcbb Family

Description Pcbb Family

These are dangerous memory resident parasitic encrypted (except "Pcbb.1141") viruses. They hook INT 9, 1Ch, 21h and write themselves to the end of COM files that are accessed. They also may infect the data files, that is the result of bug in the virus.
The infected files have the text string at the end of the file:
PCBB

These viruses check the keyboard input, and after some keystrokes they change the EGA palette. The viruses contain the encrypted strings:
"Pcbb.1141": Pc Byte-Bandit (c) VaXiNe '92
"Pcbb.1656": Pc Byte-Bandit (c) NoViA 1992
"Pcbb.1658": Pc Byte-Bandit (c) Demoralized Youth 1992
"Pcbb.1658.b": Pc Byte Bandit ver5
"Pcbb.1701": <> Demoralized Youth <>
PCBB, version 3.0 Written by <: Charlie! :>
"Pcbb.1800": Patrick Koehrs R.B R.B. Pc Byte Bandit, version 0.70

"Pcbb.1656,1658" corrupt NewEXE files: they overwrite the DOS part of these files with a small program that deletes the host file being executed. The viruses also overwrite a part of NewEXE file with the text:
This is thy present world, said the Flame to the Spark.
Thou art myself, my image, and my shadow. I have clothed
myself in thee, and thou art my vehicle to the day, "Be
with us," when thou shalt re-become myself and others,
thyself and me.

"Pcbb.1658.b,1701,1800" viruses contain seven different variants of decryption routine. They select one of these routines according to day number, append this routine to the file and then encrypt and write into the file their bodies.
"Pcbb.2277" is not a dangerous virus. It hooks INT 9, 1Ch, 21h. This virus manifests itself with a video effect. It contains the text string
5FI5SH5&W5HA5LE

While infecting that virus appends to the file the random number of NOP opcode, decryption code and encrypted virus body. The virus selects the decryption routine from 7 different variants.
"Pcbb.3072.*" are the variants of "Pcbb.2277", they contain the strings:
5FI5SH5&W5HA5
When you are demoralizedall. there is NO way out!
PCBB

They also contain the strings:
"Pcbb.3072.b": PCBB v11 (c) Hannibal Lechter of Demoralized Youth Norway.
"Pcbb.3072.b": Pc Byte Bandit, version 0.71
"Pcbb.3072.e": PCBB v11 (c) -*DRE/MER*- of Demoralized Youth

Pcbb.J4j
There are harmless memory resident viruses. They hook INT 21h and write themselves to the end of COM files that are executed. The viruses contain the word:
J4J

and:
"Pcbb.J4j.833": Jump 4 Joy, alpha-release. Not to be distributed!
"Pcbb.J4j.1273": Eloï, Eloï, lamá sabaktáni?
Charlie says: Support ()DEMORALIZED YOUTH()

Check other viruses! Be aware! Use Antiviral Software

ChDir.422

Description ChDir.422

These are memory resident dangerous viruses. They hook INT 21h and on calls to ChangeDir (AH=3Bh) DOS function they search for .COM- and .EXE-files and overwrite block of code in the file middle. The infected files are not recoverable.

Cheap.828

Description Cheap.828

It is not a dangerous nonmemory resident encrypted parasitic virus. It searches for COM and EXE files, then writes itself to the end of the file. On 4th, 12th, 17th and 25th of any month it 500 times displays the text:
ChEaPeXe v2.0 Virus
by Wâr läDÉ '97 USA

Then all next "generations" of this virus display these messages on any execution - not depending on the system date (bug in the virus?).

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com