Virus Database


Rycho Family

Description Rycho Family

These are not dangerous parasitic viruses. They search for EXE files and writes themselves to the end of the file.
"Rycho.1024.a" and "Rycho.1536.a" are nonmemory resident viruses. "Rycho.1024.b" and "Rycho.1536.b" are memory resident ones, they hook INT 1Ch, 21h and search for .EXE files when any program is executed.
"Rycho.1024.b" changes the video fonts so that the characters stays invisible. "Rycho.1536.a,b" display the messages:
"Rycho.1536.a": A.N.F. WalczyallPunx not dead...!!! #VIR v1.41
"Rycho.1536.b":
+----> UWAGA - wirus `ASIULA` <---+
¦ Marry Christmas and Happy New ¦
¦ Year. Ha,Ha my friends. RYCHO G.¦
+---------------------------------+
Rycho.Babol.2048
It is a harmless memory resident parasitic virus. It hooks INT 13h, 21h.
While selecting new disk the virus searches for EXE files, and writes
itself to the end of the file. The virus contains several routines that are
never called. The virus contains the text strings:
(C) Dj.Babol
*Made in Poland *Greetings to M.Sell
*Beda z ciebie ludzie ..sie smiali!*.COM Äis safe!
You are death*Pozdrowienia dla w.wirusowcow!
*.EXE



Check other viruses! Be aware! Use Antiviral Software

Olivia.3378

Description Olivia.3378

This is a very dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. Duplicate infection is possible. In some cases, the virus writes the "jump-to-virus" instruction to the middle of COM files. The virus checks the names and do not infect the following files:
4DOS, COMMAND, WIN, EMM386
The virus uses anti-debugging tricks and disables several anti-virus resident monitors. On April 10th it launches its trigger routine. This routine checks the CD-ROM installed and displays the following message:
please put a love music CD into your CD-ROM
and pass any key to continueall
Then it summons several system CD-ROM access functions (plays CD-ROM?). Then the virus displays some text (possibly in Chinese) including the text:
By André '97/1/30
In addition to listed above, it also infects Windows32 PE executable files. The virus writes its code to the end of the file in the newly created section, and modifies PE header. The virus does not spread itself from PE files. It just summons some Windows Kernel function (displays a text?), and returns to the host program. The virus has bugs and corrupts PE files while infecting them. When infected files are executed, Windows displays a standard error message, and terminates the infected application.
When an infected DOS file is executed, the virus hooks INT 21h and infects files that are accessed. When ARJ, RAR, PKZIP, LHA, BACKUP, MSBACKUP, CPBACKUP, CHKDSK or XCOPY utilities are executed, the virus disables its infection and semi-stealth routines. When VT* or PV* files are executed, the virus temporarily hooks INT 10h for an unknown reason.
The virus calls its trigger routine to play a CD disk on April 10. Before playing the CD, it displays the following message:
Put a Audio-CD into the CD-ROM, and it any key...
The virus also contains the text:
Olivia Virus 6.00.95a

Omega.440

Description Omega.440

It is a very dangerous nonmemory resident parasitic virus. It searches for .COM-files, then writes itself to the end of the file. On Friday, 13th the virus displays the Omega character (EAh ASCII), and erases the hard drive sectors.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com