Quark.1600
Description Quark.1600
It is not a dangerous memory resident parasitic virus. It hooks INT 15h, 21h and writes itself to the end of COM and EXE files that are executed. By hooking INT 15h the virus intercepts keyboard on old-style (PC-286) computers and changes keyboard data. The virus contains the text strings: smothered to inertness by bendelosangeles Arg~AdeN
If this string is changed, the virus deletes the host file.
Check other viruses! Be aware! Use Antiviral Software
Socha.753
Description Socha.753
It is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of .COM files that are opened. The virus activates only if the system date is set to 1981. When any file is executed (except ME$.OVL and NCMAIN.EXE), the virus appends a command line to the file C:M_EDITME$.OVL. The virus contains the strings: Socha C:m_editme$.ovl comCOM
Sochi.703
Description Sochi.703
It is a very dangerous nonmemory resident parasitic virus. It searches for .COM files, then writes itself to the end and to beginning of the file. The virus writes a part of its code (395 bytes) to the beginning, and the rest of the virus and the original file beginning to the end of the file. The virus overwrites the MBR of the hard drive with a trojan program that contains the counter, and decreases that counter on each booting. Starting from 40th booting from the hard drive the trojan displays the message: Enter password:
and contains bootstrap process. While 60th booting the trojan erases the MBR of the hard drive. That trojan also contains the standard bootstrap code, loads and executes the active boot sector of the hard drive. As the standard bootstrap loader the trojan contains and displays the text strings: Invalid partition table Error loading operating system Missing operating system
The virus also contains the text: *Ks&I* Sochi Olympic Games 2002
|