Saratov.1790
Description Saratov.1790
It is not a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of .COM and EXE files that are executed or opened. The virus corrupts the CHKLIST.MS file, if is exists, while infecting a file the virus checks the file name, and does not infect the files from the list (three symbols per name): EVRWD.800COMDRWANTAIDWEBWINKRNSCACLEPT.
The virus also scans the screen buffer for "Web" string, and terminates infection if that string is found. Depending on the system timer the virus displays the message: Thanks for using Saratov software.
The virus intercepts the execution of the programs with "/c vir" argument and may have to display the message followed by virus' "generation" number, but fails. The message is: The File Corrector v2.0. Made in Saratov. Serial #
Check other viruses! Be aware! Use Antiviral Software
Grunt.344
Description Grunt.344
These are dangerous not memory resident encrypted parasitic viruses. They search for .COM-files and write themselves to the file's ends. "Grunt" viruses erase disk sectors or files, they also type messages. These viruses contain the internal text strings: "Grunt.344,346": [GRUNT-1] -=> Agent Orange '92 <=- *.com
"Grunt.359": ALLERBMU NORI+ (C) 1991 by SMAUG in MÜNCHEN, DEUTSCHLAND!
"Grunt.427": [GRUNT-2] -=> Agent Orange '92 <=- Rock of the Marne, Sir!
"Grunt.473": [GRUNT-3] -=> Agent Orange '92 <=- This is a hot LZ all Eradicating the Enemy!
"Grunt.529": [GRUNT-4] *.COM TBFILXXX .. -=> Agent Orange '92 <=- Nothing like the smell of napalm in the morning!
GS.525
Description GS.525
This is a harmless memory resident virus which hooks INT 21h and infects by standard way the COM-files that are started which begin from JMP NEAR (E9h) opcode only. The string "GS/02" is present at the beginning of infected files and at the virus entry point.
|