Virus Database


Rotceh

Description Rotceh

It is a very dangerous memory resident boot virus. It hooks INT 13h and writes itself to the boot sectors of floppy disks and to the MBR of the hard drive. While infecting a floppy disk the virus writes the original boot sector to the 7th sector of the disk. This sector is one of FAT sectors, and as a result the virus corrupts FAT on the floppy disks. The virus checks the system date and in November it tries to erase the disk sectors, decrypt and display the message, but it has a bug and in any case returns from this routine without any harm. The message is:
Claudia H.E.:
Quisiera poder no sentir, lo que ahora quisiera poder olvidar.
Te ama
rotcéh

Check other viruses! Be aware! Use Antiviral Software

FatherVirus.456

Description FatherVirus.456

It's a not dangerous memory resident parasitic virus. It copies itself into DOS data area at address 0000:0538, hooks INT 21h and writes itself to the end of COM-files that are executed. On December, 24th it displays the message:
+---------------------------------+
¦ Merry Xmas & a Happy New Year ¦
¦ from Father Virus! ¦
+---------------------------------+

Fatty.3008

Description Fatty.3008

It is a very dangerous memory resident multipartite virus. It affects .COM and .EXE files as well as the MBR of the hard drive and boot sectors of the C: drive and floppy disks. While infecting .EXE files the virus may corrupt them.
When an infected file is executed, the virus infects the MBR and the boot sector of C: drive, hooks INT 8, 9, 13h, 17h, 21h and stays memory resident. While loading from infected disk the virus hooks the same vectors except INT 9, 21h, waits for DOS loading process and hooks INT 9, 21h.
By hooking INT 21h the virus infects .COM and .EXE files that are created and then closed, as a result the virus avoids CRC checkers. INT 13h hook is used for stealth and floppy disk infection. INT 8 hook is used to hook INT 9, 21h while installing from infected disk and for trigger routines. INT 17h is used for "Are you here?" call while installing memory resident.
Trigger routines: by hooking INT 9 the virus depending on its random counter either "skips" one key, or stuffs random key into keyboard buffer. Depending on its counter (INT 8) the virus also stuffs some sequence of keys to the keyboard buffer. Depending on the system date the virus modifies some data on disk (erases data?).
The virus contains the text strings:
XFATTY by SULPH (c)97
*Manufactured in Vsetin (CZ)
*THANX to Grisoft & Borland
*BIG KISS to my GIRL
*Have FUN, see YA!!X
.COM.EXE

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Hermannsdottir, GudbjÖrg
Gj-s Bilservice E.f.t.
ALGOTHSSONS ALLSERVICE
Green Cargo Ab
Ab NykÖpings BilvÅrd

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com