Starship
Description Starship
This is a memory resident and not dangerous stealth polymorphic virus. It infects only newly created COM- and EXE-files on the A: and B: drives. The virus also infects MBR of the hard disk if an infected file is started. As a result of this policy the virus stays resident in memory and can be moved to other computers with the minimum of the infected objects. So it is more difficult to find the virus. There is one more reason to use such a policy: when only newly created files are infected there is no need to control the DOS fatal errors (INT 24h). The virus infects files in a standard way using the polymorphic mechanism. To infect a disk the virus puts itself into the last sectors of it, replaces the active boot sector address in the Partition Table with its own starting address. During an access to MBR or to the last sectors the virus uses stealth mechanism. The virus infects the memory during rebooting from an infected disk. It places some part of its TSR copy into the interrupt vectors table (0000:02C0) and into BIOS Data Area (0000:04B0); the main part of the code is placed into the video RAM (BB00:0050). When the operating system is loaded the virus looks for other programs. If some program has been swapped from the memory (Exit - INT 20h, INT 21h and ah=0 or 4Ch) the virus moves from the video RAM to the place of the program. If a program remains resident (Keep - INT 27h, INT 21 and ah= 31h) the virus "attaches" its code to the program body. The virus recovers its main part in the video RAM if this part has been corrupted, and does this from the disk. Depending on the internal counters the virus "beeps" using Morse code and shows "stars" on the screen. It contains the string ">STARSHIP_1<". The virus hooks INT 13h, 20h, 21h, 27h.
Check other viruses! Be aware! Use Antiviral Software
M_Five.844
Description M_Five.844
This is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. The virus also searches and infects COM and EXE files upon selecting a new directory. On Fridays, the virus decrypts and displays the following message: This program has been infected by M-FIVE virus
On Tuesdays at 5:00 and 17:00, it erases the hard drive sectors.
M5VP2.1678
Description M5VP2.1678
M5VP2.1678 is a not dangerous not memory resident encrypted parasitic virus. It searches for COM-files and writes itself at their ends. Depending on system time it displays the message: +-----------------------------------------------------------+ ¦ Program, który wlasnie uruchomiles jest zarazony wirusem ¦ ¦ M5-VP2. Wirus ten jest lagodny i niczego nie uszkadza. ¦ ¦-----------------------------------------------------------¦ ¦ Jezeli jestes zainteresowany nabyciem wersji zródlowych, ¦ ¦ wyczerpujaco skomentowanych, nastepujacych wirusów: ¦ ¦ Enrico-Pro (Companion Virus), M2, M2b, M3, M4, M4b, ¦ ¦ 1-May (Socialism-II), 4DOS-Friend, v286, to zadzwon do 31 ¦ ¦ maja: Zielona Góra, telefon grzecznosciowy: 72-785, TYLKO ¦ ¦ W PONIEDZIALKI (robocze) od 18.30 do 19.30. ¦ ¦ Cena dyskietki: 120.000 zl. ¦ +-----------------------------------------------------------¦ ¦ Po 01.06.1993 podany powyzej telefon jest nieaktualny. ¦ +-----------------------------------------------------------+ Press any key to continueall
It also contains the internal text string: M5-VP2 Virus
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Tonys StÄdservice I Stockholm Ab Incari Compani Handelsbolag Svarvaren Handelsbolag Yr Invest Ab Scandinavian Stream Ab
|