Virus Database


Ukraine Family

Description Ukraine Family

These are very dangerous memory resident polymorphic parasitic stealth viruses. They hook INT 21h, and write themselves to the end of COM, EXE and OVL files (except COMM*.* ¿ DROZ*.*) that are accessed. The viruses check the file name by using the string:
.com.exe.ovlcommdrozarj.rar.pkziain.lha.chkd

and disable their stealth routines while executing several file compression utilities (ARJ, RAR, PKZIP, AIN, LHA), and disk checking utility CHKDSK.
On the 24th of any month, the viruses hook INT 1Ch, display the Ukrainian national flag, play a tune, decrypt and display a message in Ukrainian, and erase the disk sectors.

Check other viruses! Be aware! Use Antiviral Software

HarmWare.3483

Description HarmWare.3483

These are memory resident parasitic polymorphic viruses. They hook INT 21h and write themselves to the beginning of COM and EXE files that are executed. While infecting a file the viruses compress its body by an internal compression routine, as a result the file length does not grow. The viruses delete the anti-virus data files CHKLIST.MS, CHKLIST.CPS.
The viruses use on-the-fly encryption: the virus' subroutines are encrypted not only in files, but also in its TSR copy. The viruses decrypt them in case of need, execute, and then encrypt with new key. The viruses also use anti-debugging tricks.
HarmWare.3515
It is a very dangerous virus. Under debugger it erases disk data. It contains the text:
- HarmWare v1.06 by Ak Kort [SOS group] -
Hi! I'm still alive :) Let me introduce my new release.
There are none distruction. Just another way of anti-heuristicall

HarmWare.3716
It is not a dangerous virus. It also hooks INT 8, 9 (timer and keyboard) and by hooking these interrupts runs its video effect - if there are no keystrokes within 10 minutes, the virus "shifts" the screen. When the ADINF anti-virus integrity checker is executed, the virus stuffs the ENTER key into keyboard buffer and blacks the top half of the screen.
The virus contains the text strings:
- HarmWare v1.05 by Ak Kort [SOS group] -
Final version. Wait new releases.
Diskinfoscope ADinf

Harpy.1219

Description Harpy.1219

These are very dangerous memory resident encrypted parasitic viruses. They hook INT 21h and write themselves to the end of .COM and .EXE files that are executed or opened. Depending on the system date the viruses corrupt files instead of infecting them, and display the messages:
"Harpy.1219": Tehran`s Nights. Viruse
"Harpy.1750": This is a Harpy Viruse..

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com