Virus Database


Tiso.1279

Description Tiso.1279

This is a harmless memory resident multipartite encrypted (in files) virus. It infects both COM and EXE files. On execution of infected file it hits MBR of hard drive. On loading from infected disk it hooks INT 08h, waits for DOS loading and then hooks INT 21h. It writes itself at the end of files that are executed.
This is a stealth virus on accessing to infected hard drive, it hooks INT 13h to use that function.
Sometimes this virus decrypts and displays:
Nech zije Jozef Tiso, prvy slovensky prezident !

Check other viruses! Be aware! Use Antiviral Software

ShuHard.386

Description ShuHard.386

It is not a dangerous(?) memory resident parasitic virus. It copies itself to Interrupt Vectors Table, hooks INT 21h and writes itself to the end of COM files (except COMMAND.COM) that are closed. While infecting a file the virus uses not documented DOS calls and System File Tables.
When files are executed the virus scans the command line for "doom" text. If it is found, the virus modifies the i386 register CR0 - it sets on the reserved bit (CR0 OR 40000000h). The virus also reverses that bit when any program is executed.
The virus contains the text strings:
doom
VM
DOOM MD! R.ShuHard 1997

Shutdown.644

Description Shutdown.644

This is a dangerous non-memory resident parasitic virus. It searches for COM files, and writes itself to the beginning of the file. In March, it erases the disk sectors and displays the following:
Computers must be shutdown to dedicate my sister!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com