Piaf.1859
Description Piaf.1859
It is not a dangerous memory resident parasitic encrypted virus. It hooks INT 21h and infects COM and EXE files that are executed, opened or renamed. It writes itself to the beginning of COM files and to the end of EXE files. It does not infect the files with the names which begins with two symbols that present in the string: NDIOOSUVRAIVFP
I.e. the virus does not infect the files ND*.*, IO*.*, etc. If this virus cannot install its TSR copy, it displays the message "Incorrect DOS version" and returns to DOS. While installing it traces INT 13h, 21h and searches for specific code in DOS code area, that information is used while infecting the file to disable antiviral monitors. Some infected files display when they are executed: <PIAF> Copyright (c) 1991-1992 by Xxxxx III!
This virus also contains the text strings: PIAF EXECOM
Check other viruses! Be aware! Use Antiviral Software
CrazyEddie
Description CrazyEddie
It's a memory resident very dangerous virus which searches for COM- and EXE-files and hits them by standard way. While starting it overwrites MBR of hard drive. It stays TSR when infected file started only. It crypts the contents of the directories and the files by using the difficult algorithm. It hooks INT 01h, 08h, 13h and contains the text "Crazy Eddie".
CrazyPriest.1416
Description CrazyPriest.1416
It's a dangerous not memory resident parasitic virus. It searches for .COM- and .EXE-files and writes itself to their ends. Depending on the system date it deletes the files on infection, erases MBR of C: disk and displays the messages in Russian and: Hello i'm virus Crazy Priest !!! HAPPY BIRTHDAY CRAZY !!!
It also contains the internal strings: by CRAZY *.* COMMAND.COM
|