Pcflu.2134
Description Pcflu.2134
This is a not dangerous memory resident parasitic polymorphic virus. It hooks INT 21h, 27h and writes itself to the end of EXE files and to the beginnings of COM files, some "Pcflu" infects only EXE files. While executing it checks the system and sometimes displays the message: Incorrect DOS version Then it returns to DOS. The virus contains the text string: PC-FLU Mk II by Wizard 1991 Some of the viruses from this family hooks INT 8 (timer) and 9 (keyboard) sometimes. Then they periodically 'skip' the keys that are entered.
Check other viruses! Be aware! Use Antiviral Software
HTML.NoWarn.a
Description HTML.NoWarn.a
This a family of parasitic HTML infectors. They search for HTML files on the local drive and affect them. The original "NoWarn" virus was written by the same person that wrote the HTML.Internal virus and uses the same way to infect HTML files: the infection routine is a script written in Visual Basic, and the header of infected HTML file contains the reference for this script. The virus activates its infection routine depending on the system random counter with probability 1/6, it then searches for HTM, HTML and HTT files in the current and parent directories and writes itself to the beginning of the file without any damage for the host file data. The virus uses a trick to hide the ActiveX warning message: it tries to cover it with its own message window that "inform" the user: Are you sure you want to view the contents of this HTML document?
This trick works correctly only if the Desktop area is set to 800x600 pixels, otherwise the virus message does not cower the ActiveX warning. There are several virus versions known. After infecting HTML files they write the text to the browser status line: "NoWarn.a": HTML.NoWarn v0.1 /1nternal "NoWarn.b": HTML.NoWarn v0.11 /1nternal "NoWarn.c": HTML.Guess you shouldn't done that!!! /SwedisHit ADOLF
HtTM.285
Description HtTM.285
These are a harmless memory resident encrypted parasitic viruses. They hook INT 21h and write themselves to the end of COM files that are executed. The viruses do not manifest themselves, they contain the text strings: this one is unTBSCANable: die you loosy MOTHERFUCKER! [HtTM] March '94
|