Basilisk.1639
Description Basilisk.1639
It's a not dangerous memory resident parasitic polymorphic virus. It is a variant of the Eddie viruses. It hooks INT 21h, 27h and writes itself at the end of COM- and EXE-files. On execution of SCAN*.* program it types "Packed file is corrupt" and returns to DOS. It also contains the internal text strings: Basilisk v1.0 (c) 1992 YAM/RABID International The slave thinks he is released from bondage only to find a stronger set of chains
Check other viruses! Be aware! Use Antiviral Software
Odehnal
Description Odehnal
These are very dangerous memory resident parasitic polymorphic and stealth viruses. They trace and hook INT 21h, stay memory resident and then write themselves to the end of COM and EXE files that are accessed. The viruses do not infect the anti-virus programs and several utilities: AVG SYS SCAN CLEAN WIN TBAV PROT GUARD VS 286 386 DSK
When CHKDSK is run, the viruses disable their stealth routines. In some cases when listed above programs are executed, the viruses display the message and disable executing: I don't like this program !
The viruses use anti-debug tricks. Under debugger they display the message and halt the computer: BE CAREFUL !
Depending on their internal counters the viruses hook INT 9 (keyboard), corrupt the CMOS, display the message: GRISOFT(c) SOFTWARE 1989,96
and manifest themselves with a video effect. If Ctrl-Alt-Del keys are pressed during effect, the viruses call disk formatting BIOS routine. In some cases the viruses call the same effect routine, then they overwrite the MBR of the hard drive with a program that displays on booting: CMOS-DEAD: DATA DESTROYED !
The viruses also contain the text string: Hello Mr. Odehnal !
as well as: "Odehnal.4792": EXECOM12/19/91 "Odehnal.5154": EXECOM06/12/95
Oeur.3072
Description Oeur.3072
This is a dangerous memory resident multipartite virus. Upon loading from an infected file, it hits the hard-drive MBR, and upon installation in a system memory, it hooks INT 13h, 21h, and F5h. Upon loading from an infected MBR, it also hooks INT 1Ch, which summons an installation routine when DOS is loaded in the system memory. Upon calling to the ChDir DOS command, the virus summons INT F5 that searches for EXE files, and writes the virus code to their ends. INT 13h is used to perform a stealth algorithm upon access to the infected MBR. In October, this virus overwrites disk sectors with data, which contains the string "oeur934" at the beginning. It contains internal text strings, and on Friday, it displays them backwards: $?! ynnuf uoy erA $.akrakurD all eis im izduN $.draobyeK ... em ssiK $!!! EVITCAOIDAR si KSID DRAH ruoY $!!! em KCUF ton oD $:A evird otni AZZIP tresnI ! yrgnuh ma J $setteksid owt era :A evird nI ! gninraW $$ejeiwezdr rosecorp jowT $emsat agaicw :C ajcats agawU $tceted rosecorp 4XD687 oN ! gninraW $yob diputs uoY $.K ZSUIRAM ... .J ECZSEINGA ejukydyd asuriw ogeT $AGA evol J $noisrev SOD tnerrocnI $selif erom oN $$selif desolc ynam ooT $noitcerder etacilpuD $hctamsim egap edoC $deinad sseccA $sroloc eerhct si AGV ruoY $ydaer ton SME $SURIV rof yromeM etacolla tonnaC $sretemarap KCATS dilavnI $fys ot AGIMA $moniks creimS $$LUCSOK zrpeiP $hcanalg w eizdjyzrp suzeJ $NATAS EVA $azorgz oT $aselaW z zcerP $!! corw AGA $RAWONAM evol J $daed si - PAR - OKSID - ONHET $yladep ot ylap esyL $ycicam jem do zcerp eceR $! iwoloi $?! ynnuf uoy erA $.akrakurD ... eis im izduN $.draobyeK ... em ssiK
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Gedichte Zum Geburtstag Sprachdidaktik Job In Kiev Cudowne Wczasy Nad Morzem Free Article Directory
|