Virus Database


Stoned.a

Description Stoned.a
"Stoned" family. At midnight, this virus displays the following message:
IT'S MID NIGH

Stoned.Military
In November, this virus tries to format hard drive sectors.
Stoned.Million
This virus does not save the original floppy Boot sector and types "Non-System disk" while booting from an infected floppy. It overwrites the OEM message of the floppy Boot sector with the string "1000000".
Stoned.Near.a,b
These are stealth viruses. With the probability of 1/16 they will erase the MBR and displays the text:
Near Dark

Stoned.Nichols
Sometimes this virus displays:
[Nichols] by Apache

Stoned.Nov7
In October, this virus types a face symbol (01h ASCII) while booting, and on November 7, it erases the MBR.
Stoned.PC-AT
This is an encrypted virus containing the non-encrypted text string:
PC AT

= "heart" symbol
Stoned.Rostov
While booting from an infected floppy disk, this virus has the probability of 1/32 of eraseing eight sectors on the hard disk.
Stoned.Satria
Stoned family. It displays a picture.
Stoned.Scale
"Stoned" family. It saves the Boot sector of floppies and the MBR hard drive at the address 0/0/9 (track/cylinder/sector). Sometimes it plays a tune (scale).
Stoned.Scrlock
These viruses disable writing to the hard drive if the ScrollLock key is pressed.
Stoned.Scroll
It scrolls the screen if NumLock is pressed and ScrollLock is released.
Stoned.Sex.a,b
These viruses infect disks while accessing them (INT 13h, AH=2,3). They save the original sectors (boot and MBR sectors) at the addressed 1/0/3 (head/track/sector) for a floppy disk and 0/0/8 (or 0/0/7 according to its version) for the hard disk. While loading from an infected floppy disk, the viruses, with the probability of 1/8, display the messages:
"Stoned.Sex.a": EXPORT OF SEX REVOLUTION ver. 1.1
"Stoned.Sex.b": EXPORT OF SEX REVOLUTION ver. 2.0

Stoned.Spook
While infecting the hard drive, this virus writes 8 sectors to 1--9 sectors of the hard drive, and as a result, it can erase the system information. It contains a texts:
Spook 1.0
LIM

Stoned.Swedish
This virus displays the message "The Swedish Disaster".
Stoned.Torm
While booting from an infected disk, this virus, with the probability of 1/8, displays:
Repent for ye shall be tormentedall
Tormentor B - RABID Int'nl Dev. Corp. '91

Stoned.TurboManiac
On October 19, it displays:
The Turbo Maniac was here..

Stoned.WXYC
It infects boot sectors of the floppy disks and first boot sector (not MBR) of the hard drive. It contains the strings:
JAM WXYC
WXYC rules this roost!

Sometimes it displays the latter string.
Stoned.YMP
On the 1st of every month, it displays the message "HAVE A NICE DAY (c)YMP".
Stoned.Zappa
On December 4, it erases the disk sectors and displays:
Dedicated to ZAPPA...

Stoned.Zapped
This virus erases the disk sectors and displays the message:
ZAPPED YOU!

Check other viruses! Be aware! Use Antiviral Software

Bomb.1492

Description Bomb.1492

It's a dangerous memory resident parasitic virus. It leaves itself in system memory together with the infected COMMAND.COM, hooks INT 21h and writes itself at the end of COMMAND.COM files of different drives on execution or opening the files or on DOS command GetDiskSize (AH=36h). Depending on the system time it erases disk sectors and displays the message:
---- C h i n e s e B o m b ----
( Made in China 1989 )

It also contains the internal text strings:
a:command.com B:command.com C:command.com D:command.com command.com

Bomber

Description Bomber

It's a harmless memory resident polymorphic virus. It hooks INT 21h and infects COM-file except COMMAND.COM on their running. It contains the internal text messages "COMMANDER BOMBER WAS HERE" and "[DAME]".
The characteristic feature of this infector consist of a new polymorphic algorithm. Upon infection the virus reads 4096 bytes from the random selected offset and writes this code at the and of the file. Then it writes into this 'hole' its code and starts to polymorphism. This virus contains several subroutines which generate the random (but successfully executed!) code. TRhe virus inserts those parts of random code into the random chosen position into the host file. About 90% of all the i8086 instructions are present in those parts. The part of code takes the control from the previous part by JMP, CALL, RET, RET xxxx instructions. The first part is inserted into the file beginning and jumps to next part, the next part jumps the third etc. The last part returns control to the main virus body. At the end the infected file looks like at 'spots' of inserted code.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Albatron Motherboards
How To Patent An Idea
Free Manual Website Traffic
Rijeka

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com