SMEG.Queeg.a
Description SMEG.Queeg.a
This is a dangerous memory-resident parasitic polymorphic virus. It was written by using a SMEG polymorphic engine. It traces and hooks INT 21h, and write itself to the end of COM and EXE files that are executed or opened. It also hooks INT 13h and 20h. While infecting a file, it checks the file name, and does not infects the files with names CO*.*, F-*.*, SC*.*, TB*.*, VI*.*, FS*.*, VP*.*, VS*.*, CL*.*, SM*.*, FL*.*. On Sundays, depending on the system time and its internal counters, the virus erases the CMOS and the disk sectors, and then displays the following message: +---------------------------+ ƒ -" QUEEG "- ƒ ƒ ~~~~~ ƒ ƒ (C) The Black Baron 1994 ƒ ƒ ƒ ƒ Featuring: SMEG v0.2 ƒ ƒ ƒ ƒ Better than lifeall.. ƒ +---------------------------+
It also contains the following text strings: EXECOM /:.<>+=;,"[]|OC-FCSBTIVSFPVSVLCMSLF SMEG v0.2
Check other viruses! Be aware! Use Antiviral Software
Codr.1402
Description Codr.1402
This is a very dangerous memory resident partly encrypted parasitic virus. It hooks INT 10h and 21h, and writes itself to the end of COM and EXE files (except COMMAND.COM) that are executed or opened. When the DRWEB.EXE file is executed, the virus disables its INT 21h hooker, hooks INT 22h (program terminate address), waits for the moment the program exits, and re-hooks INT 21h. Depending on the current date, the virus runs one of its trigger routines. On Friday the 13th of any month, the virus erases data on the hard drive. On the 21st of any month at 12:xx, the virus reboots the computer. The virus contains the text: COMMAND.COM DRWEB.EXE .COM .EXE
Coito.644
Description Coito.644
It's a harmless memory resident encrypted parasitic virus. It hooks INT 13h, 21h and writes itself to the end of COM- and EXE-files are executed. It contains the internal string: -= COITO, ERGO SUM =-By Green Leon 1993.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|