Tequila Family
Description Tequila Family
These are memory resident harmless stealth polymorphic multipartite viruses. They write themselves at the end of .EXE-files are executed or closed. These infectors hit MBR on execution of infected files, save the old MBR in the last sectors of C: drive and reduce its size in the Disk Partition Table. The viruses infect RAM on a reboot from the infected MBR only. They hook INT 13h, 1Ch, 21h. According to their internal counters the viruses display a colorful picture (Mandelbrot fractal set) and the message: Execute: mov ax, FE03 / INT 21. Key to go on!
After executing this instruction the viruses display: Welcome to T.TEQUILA's latest production. Contact T.TEQUILA/P.o.Box 543/6312 St'hausen/Switzerland. Loving thoughts to L.I.N.D.A BEER and TEQUILA forever !
Tequila.5volt It's a parasitic (not multipartite) variant of "Tequila" virus. It hooks INT 21h only and does not hit MBR of hard drive. It tries to install itself into UMB. This virus checks the file name and does not hit the files WIN*.*, CHKDSK*.*, BACK*.*. It contains the internal text: This is a beta version of the '-5 Volt' virus. A final and error free one will never follow because I've got enough of viruses. Now a message to the programmers of Turbo Anti Virus: You do a dangerous play with INT 21h in your TSAFE utility. It took me quite a long time to make the virus compatible with TSAFE. Please use clean programming technics in your next version. Today it's a Saturday and a big party with a lot of TEQUILA takes place! Wow!! Greetings to the U.S. Army in Iraq.
Check other viruses! Be aware! Use Antiviral Software
Pysk Family
Description Pysk Family
These are not dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of COM and EXE files. Pysk.1536 It infects the files that are executed. Depending on the current date it hooks INT 9, or INT 15h, or INT 1Ch and changes keyboard flags or scancodes (by hooking INT 15h, 1Ch), displays the message when Alt-Ctrl-Del keys are pressed (INT 9). In some cases this virus decrypts and displays one of the messages: I can't find this file, but I love you? Co to za bzdura? Cmoknij mnie w dysk!!! KEEP SMILING VIRUS PYSKKILLER v 5.47 (c) MSDRAGON SOFTWARE ALL DATA WILL BE DESTROY!!! TURN OFF COMPIUTER!!! One, two, threeall TEST SOUND Have a good time! - M.S. STRAJK! Incorrect DOS version or virus(perhaps PYSKKILLER) You are dupek! LEGIA IS THE BEST
Pysk.2464 This is an encrypted stealth virus. It infects the files that are executed or closed. When an infected file is opened, the virus disinfects it. This virus also hooks INT 8 (timer), and on each timer tick the virus calculates CRC sum of its code. If CRC sum is wrong (the code of the virus is not the same as original code) the virus reboots the computer. Depending on the system date and its internal counter that virus hooks INT 1Ch. On each INT 1Ch call the virus searches for "disk" or "dysk" string on the screen, and replaces it with "pysk" string. Depending on its internal counter the virus creates C:Q.COM file, and writes there silly memory resident COM virus. This virus contains the text strings: CHKDSK c:q.com VIRUS PYSKKILLER written by SMOK 9-IX-1994 W-wa ACID ZONE !!! W.Hury was here. COMMAND SMOK NO NAME HOST_FOR_C NEPTUN413 BAZIC DISK!
Python.1142
Description Python.1142
It is a very dangerous memory resident parasitic encrypted virus. It hooks INT 21h and writes itself to the end of .COM and .EXE files that are executed or loaded as overlays. Depending on the system timer it erases MBR of the hard drive. It contains the string: PYTHON
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|