Beer.3399
Description Beer.3399
These are not dangerous memory resident encrypted parasitic viruses. They hook INT 21h and write themselves to the end of COM- and EXE-files that are opened or executed. From 1992 they manifest themselves by sound effect and dysplay the message in Russian. Some of the "Beer" viruses are dangerous ones, on opening they overwrite some files with the text in Russian, the file names to overwrite are: DISKDATA.DTL VIRUSES.INF A-DINF-_.___ [NOTE "_" not displayable in HTML] DIRINFO -V.MSG
These viruses contain/display the messages: "Beer.3399": Lozinsky! I know you to be old beer drinker. How about a mug of beer or two? It would be amazing to meet you at our beer party. You are welcome at Solntsevo railway station About 17.00 p.m. every friday and wednesday.
"Beer.3490": AIDS617.EXE EGA - text mode demonstration Copyright (c) by Wadim 1990. I love you ,Ann !ANNA Wadim S.
"Beer.3522": DISKDATA.DTL VIRUSES.INF A-DINF-_.___ DIRINFO REPORT.WEB REPORT.TXT ADINF-C.LOG ADINF-D.LOG ADINF-E.LOG ADINF-F.LOG ADINF-G.LOG CHKLIST.MS AVPTSR.EXE -D.COM -D3.COM VSAVE.EXE ANTI4US.EXE F_PROT.LOG
Check other viruses! Be aware! Use Antiviral Software
Fva.1635
Description Fva.1635
It's a harmless memory resident virus. It hooks INT 21h and infects by a standard manner EXE-files upon their execution. It writes the TSR copy at the address 9F60:0000 without MCB correction. It also contains the text: "Fva iitd".
Fyodor.145
Description Fyodor.145
It is a very dangerous nonmemory resident overwriting virus. It searches for .COM files, then overwrites them, displays the message "Bad command or file name" and returns to DOS. The only interesting feature of this virus: it has PKZip file format, i.e. the header of file has the same ID-stamp and fields that PKZip archives have. The virus also contains the text strings: *.com fyodor
|