Triadi.3998
Description Triadi.3998
It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. The virus is rarity: COM files installer uses an opcode that is legal for XT machines only (if somebody remembers the PC-XT computers), but the sample of virus was found only in 1998 - after about seven years the virus was written. As a result of this XT-only instruction the infected COM files halts when they are executed. On tenth infection the virus manifests itself by a video effect: switches the computer to video mode, displays an image of 5" floppy disk covered with messages: Declaration Of Disk Rights We need REST!!! DISKTIRED (c) 1991, TRIADI
Depending on the system time (at 12:00 and at 19:00) the virus displays the messages and waits for "TRD" input: It's lunch time, Everybody goes to eat. Only if you can guess my initial, I'll let you pass. It's dinner time, I want to eat. I'll let you use the file, if you can guess my initial.
Check other viruses! Be aware! Use Antiviral Software
Emorph.1696
Description Emorph.1696
It's a not dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM-files that are executed. On infection of the third file it hooks INT 8, 10h, 13h also and manifests itself by different methods: launch a ball (see "Ping-Pong"-virus), changes the font table for several characters, displays the message: [1993 por JMC Ver 1.1]
It contains the internal text string also: E-Morph
Emperor.5826
Description Emperor.5826
It is an extremely dangerous memory resident polymorphic multipartite virus about 6Kb of length. It infects DOS COM and EXE files by writing its code to the end of the file, and overwrites the MBR of the hard drive and boot sector on floppy disks with its own loading routine that installs the virus into the system memory on rebooting. The virus has many anti-debugging tricks, uses stealth functions and quite complex routines to get addresses of DOS kernel to bypass anti-virus protection. The virus has bugs and in some cases it corrupts the files while infecting them, and they halt the system when executed. When an infected file is run, the virus decrypts itself, checks for its TSR copy already installed in the system, and runs its installation routine. This routine allocates a block of DOS memory, copies virus code to there, hooks INT 12h, 13h, 21h and infects the MBR of the hard drive. The virus INT 21h hooker intercepts file accessing calls, and runs infection and stealth routines. The INT 13h hooker does the same on the MBR and floppy disk boot sector reading/writing. While infecting the MBR the virus uses several tricks to bypass anti-virus protection: writes data by direct calls to HDD controller ports; or stuffs 'Y' to keyboard buffer, in case the Megatrends or AWARD BIOS is installed and VirusWarning BIOS protection is enabled (the virus checks necessary field in the CMOS memory). The virus stores the original MBR and boot sectors to the reserved sectors on the drive, but encrypts and corrupts this code so, that these data will work correctly only in case the virus TSR copy is active (i.e. only in case the disk is infected, the virus already installed its code into the memory and released control to the original bootstrap routine). The virus also patches the MBR DiskPartitionTable - it loops its tables. As a result it is not possible to load the system from clean MS DOS floppy disk, and it is necessary to use other DOS versions, or special tools to access the hard drive. While infecting the MBR or floppy disk boot sector the virus checks it for some specific code, and erases the CMOS memory if this code is found, the message "Error in CMOS" is displayed then and computer halts. The virus also has more dangerous destruction routine. It erases the data on the hard drive and corrupts the Flash BIOS in the same way the "Win95.CIH" (aka "Chernobyl") virus does. The virus at the same time displays the message: EMPEROR I will grind my hatred upon the loved ones. Despair will be brought upon the hoping childs of happiness. Wherever there is joy the hordes of the eclipse will pollute sadness and hate under the reign of fear. In the name of the almighty Emperorall.
This routine is executed if the virus founds an active debugger in the system memory, or the system is rebooted in period from 5am till 10am. This routine also may take control because of a bug in the virus code. The virus also contains the text strings: the EMPEROR virus written by Lucrezia Borgia In Colombia, 1999
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Dakramen Calling Cards Ks Car Loans
|