Virus Database


Trojan.Win32.LoveYou

Description Trojan.Win32.LoveYou

this text was written by Alexey Podrezov, Data Fellows Ltd
This Trojan, when run, shows nothing important on the screen imitating hard disk formatting and Flash Bios corruption. At the same time, it copies itself to the Windows directory and modifies the Windows registry to be run upon the next Windows start-up. It also renames WIN.COM to WIR.COM so Windows cannot be started normally any more. Even if you rename WIR.COM to WIN.COM and start Windows, the Trojan will run, repeate its activities and shutdown Windows. The Trojan also modifies some Windows settings in the registry. The only way to get rid of it is to manually delete LOVEYOU.EXE from the Windows directory (from DOS prior to Windows startup) and then rename WIR.COM back to WIN.COM.

Check other viruses! Be aware! Use Antiviral Software

Foma family

Description Foma family

These are not dangerous memory resident parasitic viruses. They hook INT 8, 21h and write themselves to the end of COM files that are executed or opened. When the AIDSTEST anti-virus is executed, the viruses display one the messages and halt the system:
Abnormal program termination
?KMON-F-System read failure halt 177640
Unrecognised error. DMA failure.

Depending on the system date and their counters the virus blink the screen or display messages in Russian. The viruses also contain the text strings:
"Foma.972": STIN V:1.02
"Foma.1000": STIN V:1.01
"Foma.1200": STIN V:1.00
( CGA/EGA/VGA Terminal Color Invertor ) 11-Nov-1991.
Kpy ¼ «p á½ ¡¿ á¼ ¿ ¡Ñ ½áí ¼ ¿ «ó¿ á¼ »« ó áÑ all.....
"Foma.1733": FOMA V:1.01
"Foma.1900": FOMA V:1.00

Foo.956

Description Foo.956

It is not a dangerous nonmemory resident encrypted parasitic virus. It searches for COM files in current and in parent directories, then in C:WINDOWS directory and infects not more than three files found. While infecting the virus writes itself to the end of the file. The virus pays attention to the internal self-checking Windows32 ability and fix the necessary date ("ENUNS" field at the end of Windows COM files) while infecting them.
The virus uses anti-debugging tricks. On 29th of any month it displays the message and halts the computer:
--FOO VIRUS--
WE'RE ALL STARS NOW, IN THE DOPESHOW
MADE IN THE UK, WE EXIST..

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Toledo Homes
Brasilian Property
Property Queenstown New Zealand
Prague Property
Karlsson, Kenneth

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com