Virus Database


TMC

Description TMC

It is a harmless memory resident partly encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are accessed. The virus infects the files on floppy disks only. The virus checks the file names and does not infect the files: NO*.*, WE*.*, TB*.*, AV*.*, F-*.*, SC*.*, CL*.*, CO*.*, WI*.*, KR*.*.
The virus uses uncommon polymorphic engine - each time the virus installs itself into the memory it mixes blocks of its code and data and inserts random data. The virus also changes data offsets in its assembler instructions, constants and so on. As a result, the virus is not 100% encrypted, but it has no constant parts of code and ever the length of virus is changed.
Being installed into the memory the virus does not changes its code anymore, and all its replications have constant set of instructions. After reboot the virus installs itself into the memory and generates new set of instruction and infects files with this new set.
The virus contains the text:
* TMC 1.0 by Ender *
Welcome to the Tiny Mutation Compiler!
Dis is level 6*9.
Greetings to virus makers: Dark Avenger, Vyvojar, SVL, Hell Angel
Personal greetings: K. K., Dark Punisher

Check other viruses! Be aware! Use Antiviral Software

GmSpirit.2655

Description GmSpirit.2655

It is not a dangerous memory resident polymorphic parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. The virus does not manifest itself in any way. The virus contains the text strings:
[GM.Spirit]
[v1.10]
[Author: Green Monster, Russia]
We live in XMSall

The virus uses many complex programming tricks:
- it stores its TSR copy in the XMS memory and leaves in DOS memory just a small routine that hooks file execution, then allocates a block of DOS memory, copies to there the main virus body from the XMS, and executes it;
- when other programs are executed, the virus is able to move this routine in DOS memory;
- to intercept file execution the virus scans DOS kernel and patches DOS handler code with JMP_Virus instruction;
e.t.c.

Gnat.753

Description Gnat.753

It's a not dangerous memory resident parasitic encrypted virus. It hooks INT 1Ch, 21h and writes itself to the end of EXE-files that are executed or loaded as overlays. Sometimes it overturns the screen. It contains the internal text string "GNAT 1.0" also.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Software For Business
Shopping
Hemorroids Cure
Kinky Wear
Luxor Furniture

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com