Virus Database


Shrapnel.6067

Description Shrapnel.6067

It is a dangerous memory resident multipartite stealth virus. It writes itself to the end of COM, EXE and NewEXE files (Windows) as well as to the MBR of the hard drive and boot sector of floppy disks.
When an infected file is executed, the virus checks the presence of MS Windows. If Windows is installed, the virus searches for EXE files in the current directory and infects them. Then the virus infects the MBR of the hard drive. If Windows is installed, the virus uses direct calls to hard drive ports to write data to the disk. The virus then returns control to the host program.
While loading from an infected disk the virus hooks INT 13h, 1Ch, waits for DOS loading process and hooks INT 21h, 2Fh. The virus then writes itself to the end of files that are executed. When PKZIP or ARJ archivers are run, the virus disables its stealth routines. The virus does not infect the files (anti-viruses, utilities, and more) TBAV, COMMAND, WIN, SCAN, AVP, F-PROT, NAV and so on according to the string (two letters per name):
TBCOWISCVIAVVAF-NAVSIVFIFVIMQBMSDODESW

The virus deletes the file:
C:WINDOWSSYSTEMIOSUBSYSHSFLOP.PDR

Depending on its counters the virus creates the subdirectory SHRAPNEL on the disk.
The virus also contains the texts:
SHRAPNEL v1.0 by PH Made in the USA
*.EXE

Check other viruses! Be aware! Use Antiviral Software

Bljec Family

Description Bljec Family

These are dangerous, non-memory resident parasitic viruses, which search for COM files of the current directory, and write themselves to their beginnings.
For several viruses of this family, the start code of the virus is the text string "Digital F/X Virus - Created on 2/5/92 by Phoney Phreak" or "XYZ Virus 1.0 - Buddy and Chloe 5/27/89". This string is executed as a code, but this code contains i286/386 instructions.
These viruses also contain the text "*?.com". In September, "Bljec.300" and "307" erase the disk sectors and display: "Sad virus - 24/8/91".

Blood.418

Description Blood.418

It is a not memory resident not dangerous virus. The .COM-files of current directory gets infection when the virus starts. The virus from time to time types: "File infected by BLOOD VIRUS version 1.20".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



CronstrÖm Design, Mechanics And Racing
Jeanette Anderssons Hyrstol
Skw-technology
Autoteknik & Hydraulik Nybro Ab
Jansson, Henrik

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com