Virus Database


Terminator.3275

Description Terminator.3275

This is a benign memory resident encrypted parasitic virus. Upon being executed, it searches for CONFIG.SYS file, inserts the string "device=vmem.sys" into that file, creates a VMEM.SYS file in the root directory of the current drive, and writes the virus dropper in the VMEM.SYS file. Then the virus returns to the host program.
While loading, DOS processes the CONFIG.SYS file and loads into the memory that infected VMEM.SYS. As a result, the virus gains control, stays memory resident as a device driver with the name "DOSxxVMS" (xx is the version of installed DOS), and hooks INT 21h. Then the virus writes itself to the end of COM and EXE files that are accessed. It does not infect the disks if there is a MICRO.BUG file in the root directory.
Depending on the current time, the virus displays the following message:
You have been stupied and careless, so now
the TERMINATOR (tm) will take over your computer.
You will get it back either when you grow up,
or get an ANTI-VIRUS.
+-------------------------------------------+
ƒRemember: Software piracy is forbidden! ƒ
ƒ DO NOT MAKE ILLEGAL COPIES OF THIS VIRUS!!ƒ
+-------------------------------------------+
It also contains the strings:
TERMINATOR
COMSPEC=
micro.bug
device=vmem.sys
A:config.sys
A:msdos.*
A:ibmdos.*
A:command.*

Check other viruses! Be aware! Use Antiviral Software

Nik.442

Description Nik.442

These are memory resident parasitic viruses. They hook INT 1Ch, 21h and write themselves to the beginning of COM files that are executed. The viruses contain the text:
NIK

"Nik.442" is a dangerous virus, depending on its counter it corrupts the CMOS. "Nik.546" slowly turns off the screen by using the VGA features.

Nikki.3133

Description Nikki.3133

It is a harmless memory resident parasitic polymorphic virus. It hooks INT 21h and writes itself to the end of COM and EXE (except COMMAND.COM) files that are executed, opened, renamed or when file attributes are accessed. The virus sets read-only attribute for infected files. The virus does not infect the programs: VIR*, CLEAN, DEBUG, SCAN, NAV. The virus deletes the anti-virus data files CHKLIST.*.
The virus contains the text strings:
TO Nikki Edval ng TorOntCan.FROM Putoksa Kawayan.
Kathang-isip sa Metro Manila, Philippines

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



India Canada Calling
Cyprus Property For Sale
Perma Clean
Iphone And Ipad
Hausbau

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com