Virus Database


Piaf.1859

Description Piaf.1859

It is not a dangerous memory resident parasitic encrypted virus. It hooks INT 21h and infects COM and EXE files that are executed, opened or renamed. It writes itself to the beginning of COM files and to the end of EXE files. It does not infect the files with the names which begins with two symbols that present in the string:
NDIOOSUVRAIVFP

I.e. the virus does not infect the files ND*.*, IO*.*, etc.
If this virus cannot install its TSR copy, it displays the message "Incorrect DOS version" and returns to DOS. While installing it traces INT 13h, 21h and searches for specific code in DOS code area, that information is used while infecting the file to disable antiviral monitors.
Some infected files display when they are executed:
<PIAF> Copyright (c) 1991-1992 by Xxxxx III!

This virus also contains the text strings:
PIAF
EXECOM

Check other viruses! Be aware! Use Antiviral Software

Arianna.3426

Description Arianna.3426

This is a memory resident multipartite, encrypted and stealth virus. While executing an infected file it infects the MBR of the hard drive. While loading from infected MBR it hooks INT 1Ch, waits for DOS loading, then hooks INT 13h for stealth algorithm while accessing to infected MBR, and INT 21h to infects the files. It writes itself to the end of EXE files that are accessed. When an infected file is opened, the virus disinfects it.
Sometimes the viruses manifest themselves with a video effect and erase the original MBR sector (not first hard drive sector, but the sector containing the original MBR that was saved while infecting a disk). The viruses contain the text strings:
Coded in BARI ThanX to DOS UNDOCUMENTED
Check the code to discover the virus name
It is very easy ! Bye !!

ArjDropper.402

Description ArjDropper.402

It is a harmless nonmemory resident virus-worm 402 bytes of length. When an infected file is executed, the virus searches for ARJ archives and appends its copy to archives that are found. The virus copy in archives is stored in format of ARJ data and has the filename RUNME.COM. This RUNME.COM file contains a copy of the virus, and being extracted from infected archive it may spread the virus code to other archives. The virus contains the text strings:
*.ARJ
ARJDrop by Qark/VLAD
RUNME.COM

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com