Virus Database


PingPong.a

Description PingPong.a
This virus is similar to "Ping-Pong". The difference is that instead of a jumping ball, it causes the setting of the 13h interrupt vector to a subroutine, which destroys the first eight sectors of a floppy disk.
Ping-Pong modified by Yankee
This is the result of a modification of the "Ping-Pong" virus by the "Yankee" virus. Every time this infector is loaded, one unit is added to the version number (special byte). When zero (255+1) is reached, the virus deactivates.

Check other viruses! Be aware! Use Antiviral Software

IRC-Worm.Claw.2513

Description IRC-Worm.Claw.2513

This is a very dangerous memory resident encrypted parasitic virus. It hooks INT 21h, and writes itself to the end of COM and EXE files when they are accessed. Then it looks for COM and EXE files in the current directory and infects them. The virus also creates a hidden file in the root directory on the C: drive, writes its copy to there and adds to the AUTOEXEC.BAT an instruction to execute this file. The virus then infects WIN.COM and COMMAND.COM in the Windows directory.
To infect mIRC and spread via IRC channels, the virus creates two files in the C:MIRC directory: the MIRC_SYS.INI virus script file and DOS COM virus dropper CYBER.COM. Then it patches the MIRC.INI file with an instruction to load infected MIRC_SYS.INI file on IRC client start-up. The virus script switches off mIRC security (warning messages) and sends the virus dropper into the IRC channel at the moment a user disconnects from the channel.
On September 1st, depending on a random value, the virus erases the FLASH BIOS. To do this, the virus calls extended BIOS functions.
When the virus dropper starts, it displays the texts:
Clawfinger

The virus also contain encrypted strings:
Do you know how it feels to be down in the dirt with a bullet
in yer breast and blood on yer shirt Lying in a bloodpool down
in a pit covered with the corpse and the blood and the shit
How does it feel to have a gun at yer head when ya know that
you'd be much better off dead Freedom has a price and that price
is blood so chase the motherfucker right down in da mud
[ WARFAIR - CLAWFINGER ]

IRC-Worm.Crack.a

Description IRC-Worm.Crack.a

This is a silly IRC worm spreading through IRC channels by using mIRC client. The worm itself is Win32 executable file about 3K of length (that is compressed executable file, being decompressed it gets about 10K of size).
When the worm file is run, it copies itself to Windows directory with CRACK.EXE name and affects mIRC client. The worm looks for mIRC client in two directories:
C:MIRCD:MIRC
While affecting the worm overwrites the SCRIPT.INI file with a set of commands that send the CRACK.EXE file (worm code) to users that join infected channel.
The SCRIPT.INI file on connecting to IRC server also joins "vxers" and "cservice" channels and sends the messages to there:
To "vxers":
I'm wide awake in my kitchen, it's dark and I'm lonely, oh if I could
only get some sleep.. Creeky noises make my skin creep. I need to get
some sleep.. I can't get no sleepall.
To "cservice":
PLEASE join #vxers, and visit http://www.shadowvx.com/4Q and
http://www.shadowvx.com/fun4vxers .. We're the best!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Phone Card
Calling Cards
Gaza
Free Software Downloads
Php Edit

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com