Virus Database


Trojan.Win32.Tepille

Description Trojan.Win32.Tepille

This trojan does not destroy data on the computer, but locks it instead.
When trojan file is run it copies itself to CLEARUP.EXE file to Windows system directory and registers it in system Registry auto-run key:
HKLMSoftwareMicrosoftWindowsCurrentVersionRun TePille = %SystemDir%clearup.EXE
The trojan then renames two system files to make system cleaning more difficult:
renames REGEDIT.EXE to REGEDIT.BAK in Windows directory renames MSCONFIG.EXE to MSCONFIG.BAK in Windows system directory
The trojan then displays fake error message and exits:
Error
Imposible cargar OCX mscommondlg.ocx, la aplicacion finalizara
[ OK ]
On next Windows startup the trojan is auto-started, locks the system and displays an image of eyes and lips. Keyboard and mouse is locked, and the only way to exit is Reset key, but on next startup the trojan is started again.
To get rid of the trojan you need to load system in safe mode, then
delete trojan file in system directory
rename REGEDIT and MSCONFIG files back to .EXE
run REGEDIT and delete trojan's registry "Run=" key

Check other viruses! Be aware! Use Antiviral Software

Mururoa.3443

Description Mururoa.3443

This is a relatively harmless, memory resident encrypted parasitic stealth virus. It hooks INT 21h, and writes itself to the end of COM and EXE files that are executed or closed. When an infected file is opened, the virus disinfects it. The virus doesn't infect several anti-virus utilities (see the string below).
On May 4, 8, and 20, it displays the following message:
+-------------------------------------------------+
| I have one mesage to all people on earth : |
+-------------------------------------------------+
| All French nuc. test`s was STOPED. But MURUROA |
| IS DEAD !!!!! I am a coder of HELL FIRE and I |
| BRING YOU >>>>>> FIRE <<<<<< By Blesk/SVL |
|NOTE: Name of this virus is [MURUROA_END] |
| By Blesk from Slovak Virus Laboratories at .SK |
| Real name of BOZA is BIZATCH.. STUPID A-VERS !!!|
| PLUTONIUM IS BETTER IN POWER-PLANT !!!! |
| My greet to: VYVOJAR,SVL,VLAD,SKIMS,40-hex,IR |
+-------------------------------------------------+
| And to some my friends: DJ.Milan,DJ.Maros, |
| DJ.Babula(Baby),TINA-huhu,DURO,LACI,Duffy,Kaaa, |
| Stano alland more... A zdravim Mira Trnku 8)) |
+-------------------------------------------------+
The virus also contains the text string:
I am in LOVE now... ZUZANKA B.B. in Slovakia <:)<8<
I love PC Revue ....
For M.T.: Vivat Ziar nad Hronom.. 8)) Uz si rad ??
RADAR v PC Revue 9/94

Mururoa.3449.a

Description Mururoa.3449.a

This is a relatively harmless, memory resident encrypted parasitic stealth virus. It hooks INT 21h, and writes itself to the end of COM and EXE files that are executed or closed. When an infected file is opened, the virus disinfects it. The virus doesn't infect several anti-virus utilities (see the string below).
On May 4, 8, and 20, it displays the following message:
+-------------------------------------------------+
| I have one mesage to all people on earth : |
+-------------------------------------------------+
| All French nuc. test`s was STOPED. But MURUROA |
| IS DEAD !!!!! I am a coder of HELL FIRE and I |
| BRING YOU >>>>>> FIRE <<<<<< By Blesk/SVL |
|NOTE: Name of this virus is [MURUROA_END] |
| By Blesk from Slovak Virus Laboratories at .SK |
| Real name of BOZA is BIZATCH.. STUPID A-VERS !!!|
| PLUTONIUM IS BETTER IN POWER-PLANT !!!! |
| My greet to: VYVOJAR,SVL,VLAD,SKIMS,40-hex,IR |
+-------------------------------------------------+
| And to some my friends: DJ.Milan,DJ.Maros, |
| DJ.Babula(Baby),TINA-huhu,DURO,LACI,Duffy,Kaaa, |
| Stano alland more... A zdravim Mira Trnku 8)) |
+-------------------------------------------------+
The virus also contains the text string:
I am in LOVE now... ZUZANKA B.B. in Slovakia <:)<8<
I love PC Revue ....
For M.T.: Vivat Ziar nad Hronom.. 8)) Uz si rad ??
RADAR v PC Revue 9/94

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Php Proxy Server
Per Hollartz Aktiebolag
Tunabygdens Vvs-installatÖr Ab
Stegpanzerketten

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com