Virus Database


Ph33r

Description Ph33r

It is a harmless memory resident parasitic virus. While executing an infected program the virus hooks INT 21h and stays memory resident. In case of DOS host file the virus uses the standard methods of the INT 21h hooking, in case of NewEXE file the virus uses DPMI calls.
While opening, execution, renaming executable files including NewEXE, and on changing the file attributes the virus writes itself at the end of the file. The virus checks the file length and infects only *.DL*, *.CO* and *.EX* files. The virus does not infect the *AV.*, *DV.*, *AN.*, *OT.* files.
While executing COM and EXE files the virus writes itself to the end of the file. While infecting a NewEXE file the virus moves NE header 8 bytes up, creates new descriptor there, and writes itself the end of the file.
The virus does not manifest itself. It contains the text strings:
=Ph33r=
Qark/VLAD

On October 21st "Ph33r.1460" displays:
Cheng Cheng:
Happy Birthday to you, HandSome Boy!

This virus also contains the text:
> Joan for Windows v1.0 of T.N.T. Taipei/Taiwan 1995/09 <

Check other viruses! Be aware! Use Antiviral Software

Drizzle.1600

Description Drizzle.1600

It is a dangerous memory resident parasitic virus. It hooks INT 16h, 21h and writes itself to the end of .COM files (except COMMAND.COM) that are executed. The virus runs a counter in the MBR of the hard drive and increases this counter on each installation into the memory and on each infection. When counter reaches 400h (1024) the virus corrupts the MBR code, and it will halt the system on next booting. When this counter reaches 256, the virus starts to change keys that are entered (INT 16h) and delays on any keystroke. The virus contains the only text string:
COMMAND.COM

DrJohn.2000

Description DrJohn.2000

It is not a dangerous memory resident parasitic virus. It writes itself to the end of COM and EXE files. When an infected file is executed, the virus infects the C:COMMAND.COM file, then hooks INT 13h, 21h and infects the files that are opened. Depending on the system date (one month after infecting) the virus displays the message in Russian. The virus also contains the text strings:
c:command.com
*Doctor John*!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



FINNVEDEN SKOLTRANSPORTER AB
Keodomino NorrkÖping Ab
Trafokonsult Sweden Ab
BALTICGRUPPEN FASTIGHET AB
VALMIC FÖRSÄLJNINGS AB

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com