Salieri.1745
Description Salieri.1745
It is a very dangerous memory resident parasitic virus. It hooks INT 17h, 21h and writes itself to the end of .COM and EXE files that are accessed. The virus separates the files for the programs and the data files by the file name extension (.COM) and MZ stamp at the beginning of EXE files. While infecting a file the virus checks the file name and does not infect the files: SCAN.EXE CLEAN.EXE RAWCOPY.EXE TNTVIRUS.EXE MSAV.EXE VSHIELD.EXE DETECTOR.EXE
Depending on the system timer and the data that are printed the virus exchanges the symbols according to the string: AUEIOUVBvbCKckGJgjMNmnYIiyZSzsXSxsáaéeíióoúu1736942508,.;:+-*/?¿/ºª
The odd symbols are replaces with the next ones, the even symbols are replaced with the previous ones ('A' <-> 'U', 'E' <-> 'I', e.t.c.). Depending on the system timer the virus also hooks INT 13h and disables writing to the disk (except the period when the virus is infecting a file). That may corrupt the data and halt the computer. The virus also contains the text string: Programado en Sevilla por Salieri
Check other viruses! Be aware! Use Antiviral Software
Rash.1737
Description Rash.1737
It is a harmless memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are executed or closed. When infected files are opened, the virus disinfects them. The virus does not manifest itself in any way, it contains the text string: - Rash97 -
Rasputin
Description Rasputin
It is not a dangerous memory resident stealth boot virus. It is encrypted in sectors and well as in the system memory. It hooks INT 13h and writes itself to the MBR of the hard drive and the boot sector of the floppy disks. Location on a disk is in free clusters which virus marks as BAD (pseudo-bad clusters). While loading at 4am the virus decrypts and runs a video-effect and displays the text: RASPUTIN Coded By Blue Skull
|