Baphometh.1536
Description Baphometh.1536
It is a dangerous memory resident multipartite virus. It infects the MBR of the hard drive, boot sector of floppy disks and writes itself to the end of COM and EXE files that are executed. While infecting the MBR the virus overwrites the Disk Partition Table, as a result the MBR cannot be disinfected by the "FDISK /MBR" command. The virus also deletes the C:WINDOWSSYSTEMIOSUBSYSHSFLOP.PDR file. It contains the encrypted text string: Baphometh v2 ~CAD
When an infected file is executed the virus infects the MBR, hooks INT 21h, stays memory resident and then affects executable DOS files. On loading from infected disk the virus hooks INT 8 (timer), INT 13h, waits for DOS loading process and then hooks INT 21h. By hooking INT 13h the virus runs its floppy disk infection and stealth routines - on accessing to infected MBR or boot sector the virus replaces it with its original code and data.
Check other viruses! Be aware! Use Antiviral Software
Gipro.504
Description Gipro.504
It's a harmless not memory resident parasitic virus. It searches for EXE-files and writes itself to their ends. It contains the internal text string: -=_ G.I.Pro.V. _=-
Girl.2273
Description Girl.2273
It's a dangerous memory resident virus. It only infects the files pointed to by the 'COMSPEC=' string. The virus checks the file format for COM- or EXE-files infection. This virus contains the file name list and erases the files from this list: users.bbsfiles.bbs ly-girl.lzh srcr301.arj wolf-1.arj arwlf.lzh arj205.exe
After infection the virus types "Runtime error 213 at 2BA7:0387." and hangs up the computer.
|