Virus Database


Bashar.670

Description Bashar.670

These are dangerous memory resident encrypted parasitic viruses, to decrypt themselves they use i387 instructions in decryption loops. They hook INT 21h and write themselves to the end of COM files that are executed. Because of a bug they may corrupt files while infecting them. The viruses contain the text string:
"[Bashar_Teg] by C.W. - 1997 (JAofM)"

Check other viruses! Be aware! Use Antiviral Software

Nostardamus.3584

Description Nostardamus.3584

It is a very dangerous virus, in some cases it searches for C:*.* files and deletes them.
It uses INT 22h hook to wait the host program termination, hooks INT 21h and installs itself memory resident. It's a stealth virus, while accessing to an infected file it disinfects it. It checks the file name and do not infect several anti-virus programs.
This virus checks the file name by using the strings:
COMEXEOVLOVR
PROSCAEXTWEB
ARJRARLHAZIP
COMWINCHK
and does not infect these files or disables its stealth routines.
This virus also contains the strings:
-=Unlimited Grief=-
Kiev'96
EMME 3
Killer

Nostardamus.5995

Description Nostardamus.5995

This is a very dangerous memory resident polymorphic parasitic virus. It hooks 21h and writes itself to the end of COM and EXE files that are accessed.
Depending on the system timer and its internal counters this virus also hooks INT 10h, or INT 16h, or INT 1Ch (depending on the virus version) and manifests itself by several effects: it corrupts the files, erases the disk sectors, changes the keystrokes that are entered, displays the message:
HOME RUN !!!
The viruses also display:
The NOSTARDAMUS.Maverick (CopyLeft) Version 3.2 ultra by Populizer
Formatting disk X: 40M
It also displays about 100 stupid messages in Russian and English:
Invalid user. Unknown error !
Good user - Dead user !!!
Insert new user and press ESC
I'm big RUSSIAN monstr !!
System error, invalid TC.EXE.
See you later all
Formatting disk C: y/y ?
Press CTRL-ALT-DEL ...
Crazy & Co. ltd.
Insert new baks into drive A:
(C) Porno C++ 3.1
(C) Trubo Pascacal 7.0
Virus detected, system halted

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Semantic Indexing Software
Arcade Banner Exchange
Facebook Likes
Virtual Earth
Superspeed Usb Drives

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com