Ph33r
Description Ph33r
It is a harmless memory resident parasitic virus. While executing an infected program the virus hooks INT 21h and stays memory resident. In case of DOS host file the virus uses the standard methods of the INT 21h hooking, in case of NewEXE file the virus uses DPMI calls. While opening, execution, renaming executable files including NewEXE, and on changing the file attributes the virus writes itself at the end of the file. The virus checks the file length and infects only *.DL*, *.CO* and *.EX* files. The virus does not infect the *AV.*, *DV.*, *AN.*, *OT.* files. While executing COM and EXE files the virus writes itself to the end of the file. While infecting a NewEXE file the virus moves NE header 8 bytes up, creates new descriptor there, and writes itself the end of the file. The virus does not manifest itself. It contains the text strings: =Ph33r= Qark/VLAD
On October 21st "Ph33r.1460" displays: Cheng Cheng: Happy Birthday to you, HandSome Boy!
This virus also contains the text: > Joan for Windows v1.0 of T.N.T. Taipei/Taiwan 1995/09 <
Check other viruses! Be aware! Use Antiviral Software
Drizzle.1600
Description Drizzle.1600
It is a dangerous memory resident parasitic virus. It hooks INT 16h, 21h and writes itself to the end of .COM files (except COMMAND.COM) that are executed. The virus runs a counter in the MBR of the hard drive and increases this counter on each installation into the memory and on each infection. When counter reaches 400h (1024) the virus corrupts the MBR code, and it will halt the system on next booting. When this counter reaches 256, the virus starts to change keys that are entered (INT 16h) and delays on any keystroke. The virus contains the only text string: COMMAND.COM
DrJohn.2000
Description DrJohn.2000
It is not a dangerous memory resident parasitic virus. It writes itself to the end of COM and EXE files. When an infected file is executed, the virus infects the C:COMMAND.COM file, then hooks INT 13h, 21h and infects the files that are opened. Depending on the system date (one month after infecting) the virus displays the message in Russian. The virus also contains the text strings: c:command.com *Doctor John*!
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
FINNVEDEN SKOLTRANSPORTER AB Keodomino NorrkÖping Ab Trafokonsult Sweden Ab BALTICGRUPPEN FASTIGHET AB VALMIC FÖRSÄLJNINGS AB
|