Virus Database


Peasant.1243

Description Peasant.1243

This is a dangerous memory resident parasitic virus. When an infected EXE file is executed, the virus searches for a command interpreter (COMMAND.COM) by using the string "COMSPEC=", and overwrites it. The virus stores the part of the code that is overwritten into the unused sectors of the hard drive, then the virus returns control to the host program.
When an infected COMMAND.COM is executed, the virus reads its original code from the hard drive sectors, hooks INT 21h and returns control to COMMAND.COM. Then the virus writes itself to the end of EXE files that are accessed.
On Mondays, it disables the DOS functions SetDir, RemoveDir and ChangeDir; and when the files are deleted, it "hides" them with corresponding attributes, upon writing to files, the virus appends to them with the string:
"""NoImportRICE!"""

It displays the same string while terminating the programs. The virus also contains the text string:
(c)KoRea-PeaSant

Check other viruses! Be aware! Use Antiviral Software

Rosebud.912

Description Rosebud.912

This is a very dangerous memory resident parasitic virus related to the "Jerusalem" virus family. It hooks INT 21h, and writes itself to the end of EXE files that are executed. Depending on the system date (if the sum of the current day and month is equal to 30 - Jan 29, Feb 28, etc.), the virus deletes files instead of infecting them. The virus contains the text string:
WARNING : This Rosebud virus is simple, because it was made for interest.
But Next virus will be bit more complex.

Rotceh

Description Rotceh

It is a very dangerous memory resident boot virus. It hooks INT 13h and writes itself to the boot sectors of floppy disks and to the MBR of the hard drive. While infecting a floppy disk the virus writes the original boot sector to the 7th sector of the disk. This sector is one of FAT sectors, and as a result the virus corrupts FAT on the floppy disks. The virus checks the system date and in November it tries to erase the disk sectors, decrypt and display the message, but it has a bug and in any case returns from this routine without any harm. The message is:
Claudia H.E.:
Quisiera poder no sentir, lo que ahora quisiera poder olvidar.
Te ama
rotcéh

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Buy Ukraine Nude Photos
Www.denial-of-service-attacks.com
It News
Nfl Jerseys
Android Roms Free

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com