Virus Database


Res.2879

Description Res.2879

These are harmless memory resident multipartite encrypted stealth viruses. They hook INT 13h, 21h and write themselves to the end of COM and EXE files that are accessed. The viruses also infect the MBR of the hard drive and boot sector on the 1.4Mb floppy disks.
The viruses check file names and do not infect several anti-virus programs and archivers. The viruses contain the text strings, the first strings contains the identification letters for files that are not infected by the virus (two letters per name, the viruses check two last letters of names):
NFEBSTTERJIPHAAR
[RES] VVS

"Res.4258" also embeds itself to the FIDO mails (.PKT files). While embedding the virus creates its dropper with the LIFE.COM name, converts it to ASCII data by using standard UUE method, and adds these data to the end if victim message as a block of encoded data.

Check other viruses! Be aware! Use Antiviral Software

Maripuri.1942

Description Maripuri.1942

It is a very dangerous nonmemory resident parasitic virus. It searches for EXE files in subdirectory tree, and writes itself to the end of the file. If there are no EXE files, the virus erases CMOS, FAT of C: drive, and overwrites MBR of the hard drive with the program that displays the message:
Virus MARIPURI 1.0
By FredSoft C.O.
Made in Spain, IV-1.992

The virus also contains the string:
*.EXE *.COM *.*

Mark13.782

Description Mark13.782

It is a dangerous memory resident parasitic virus. It hooks INT 21h and on disk access calls searches for *.COM files and writes itself to the end of the file. While installing into the system memory the virus copies its code to the address 9000:0100 without fixing memory allocation blocks, that can halt the system.
The virus contains the text:
MARK13-Review

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



StuckatÖren Rangse & Jighem Ab
AB BOTKYRKABYGGEN
Kumla Tak Ab
Hälsovård

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com