Virus Database


ShuHard.386

Description ShuHard.386

It is not a dangerous(?) memory resident parasitic virus. It copies itself to Interrupt Vectors Table, hooks INT 21h and writes itself to the end of COM files (except COMMAND.COM) that are closed. While infecting a file the virus uses not documented DOS calls and System File Tables.
When files are executed the virus scans the command line for "doom" text. If it is found, the virus modifies the i386 register CR0 - it sets on the reserved bit (CR0 OR 40000000h). The virus also reverses that bit when any program is executed.
The virus contains the text strings:
doom
VM
DOOM MD! R.ShuHard 1997

Check other viruses! Be aware! Use Antiviral Software

PresidentB.1504

Description PresidentB.1504

This is a very dangerous memory resident encrypted multipartite virus. When an infected file is executed, the virus decrypts itself, hooks INT 13h and 21h, and returns control to the host program. While loading from an infected floppy disk, the virus hooks INT 12h and 13h, and waits for the DOS loading process and hooks INT 21h.
The virus then writes itself to the end of COM and EXE files that are executed or loaded as overlays or for debugging. Upon accessing 1.4Mb-floppy disks, the virus infects their boot sectors.
On April 26th, the virus erases the MBR of the hard drive and displays the following message:
** President B ][ **

Press.1024

Description Press.1024

It is a harmless nonmemory resident parasitic virus. It searches for EXE files of the subdirectory tree, then writes itself to the end of the file. In some cases the virus displays:
Press any key

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Thai Recipes
Breakfast Recipe
Drug Detox Drink

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com