Phardera.5824
Description Phardera.5824
This is a benign memory resident parasitic polymorphic virus. It hooks INT 21h, and writes itself to the end of COM and EXE files that are executed. The resident code of virus is also encrypted with different keys, and the virus decrypts/encrypts its routines "on-the-fly" in case of need. The virus also uses a lot of anti-debugging tricks. On the 10th of each month, the virus displays the following message: Phardera + Dianita
The virus contains the text strings: Phardera -by Phardera'95-----Batavia--------Indonesia---- RaredrahP Dianita
Check other viruses! Be aware! Use Antiviral Software
Lenin.943
Description Lenin.943
It is not a dangerous nonmemory resident parasitic virus. It searches for EXE files and writes itself to the end of the file. While infecting it does not alter the EXE entry registers, but inserts CALL FAR instruction into file entry point and alters EXE relocation table. Depending on its internal counters it displays the messages on Russian. It also contains the strings: *.EXE PATH=
Leningrad.1944
Description Leningrad.1944
These are not dangerous memory resident parasitic viruses. "Leningrad.1499,2000.b" are encrypted ones. They hook INT 1Ch, 21h and write themselves to the end of COM files that are executed. Sometimes they play a tune. "Leningrad.2000" contains the text strings in Russian and the string: Leningrad Leningrad Leningrad Leningrad Leningrad Leningrad Leningrad Leningrad Leningrad Leningrad Leningrad Leningrad Leningrad Leningrad
|