TrojanDropper.VBS.Zerolin
Description TrojanDropper.VBS.Zerolin
Programs which belong to this Trojan family are written in Visual Basic Script. They are coded to install a range of viruses on victim machines. Malicious programs installed by versions of TrojanDropper.VBS.Zerolin range from primitive key logging programs to multi-functional backdoors and worms.
Check other viruses! Be aware! Use Antiviral Software
Ghost.1447
Description Ghost.1447
It is a dangerous memory resident virus. It infects COM- and EXE-files when they are executed or opened. Before infection the infector appends to file random times of NOP (90h) instructions: +-----------+ ¦File ¦ +-----------¦ ¦90h 90h all¦ +-----------¦ ¦Virus ¦ +-----------+
The infector works only under DOS 3.30 because it uses some undocumented system areas and addresses of DOS 3.30: one part of the code the virus copies into one system buffer (I don't understand for why). It contains the text "MINSK GHOST,1991" and hooks INT 1Ah, 21h.
Ghost_2.5000
Description Ghost_2.5000
This is a very dangerous memory resident encrypted parasitic stealth-virus. It hooks INT 21h and 25h, and writes itself to the beginning of COM- and EXE-files that are executed, opened or closed. If the resulting COM-file length is out of segment (64K), the virus converts the file to EXE format. While installing its TSR copy, if there is no free system memory, the virus displays the following message, and exits to DOS: Swap file creation error at 0FAD:2DEC. Program aborted.
The virus contains code that overwrites .PAS- and .CPP-files with the following text: There is nothing in the world that I ever wanted more than to never feel breaking apart all my programs again. The spiderman is always hungry
but this code is never executed. In January, the virus corrupts the data on the hard drive, and then displays the following message (there may be any random digit instead of "000000000"), and "drops snow" on the screen: Happy New Year ! Ghost 1.0 is terminating its work now. Please waitall Write down this number : 0000000000 and pray for your data rescue.
The virus also contains the internal text strings: COMMAND.COM .COM.EXE.PAS.CPP I feel so tired. The way the rain comes down how it`s how I feel inside. I`ve been living so long with my pictures of you Remembering you standing quiet in the rain
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Områdesikring Homes In South Africa Miranda Homes Platzreife Computer Und Internet
|