Virus Database


Unknown_II.5559

Description Unknown_II.5559

It is a harmless memory resident polymorphic and stealth parasitic virus. When and infected file is executed, the virus decrypts itself, hooks INT 21h, 22h and executed the host file. To hook INT 21h the virus scans the DOS kernel, patches INT 21h DOS handler with bytes CDh 29h (INT 29h call) and patches INT 29h DOS handler with "JMP FAR Virus" instruction.
The virus traces INT 13h, 21h, 40h, gets their original addresses and uses them while infecting files. The virus infects COM and EXE files (except IBMBIO.COM and IBMDOS.COM) that are accessed. While infecting the virus writes itself to the end of files. On opening an infected file the virus disinfects it.
The virus contains the text strings:
IBMBIO IBMDOS
Unknown 1.0

Check other viruses! Be aware! Use Antiviral Software

Lilo.1573

Description Lilo.1573

This is a relatively harmless memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of COM and EXE files that are executed. On the 13th of any month, the virus, depending on the system time, displays messages (see below), and either returns to DOS or reboots the computer.
The virus also contains the following texts:
LI_LO.1573 virus v.0 (test) by P&C
COMMAND.COM.EXE

The messages are:
Divide error
Program too big to fit in memory
+------------------------------------------------------------------+
| If you want to be more SEXY, you must drink a lot of Pepsi ! |
| |
| XXXX XXXX |
| XXXX XXXX --+-- +-- |
| XXXX XXXX | +--+ +- |
| XXXX XXXX | | | +-- |
| XXXXXXX XXXX | |
| XXXXXXX XXXX |
| +--+ +-- +-- -+-- |
| Greetings to +--+ +- +-+ | |
| Marek Sell +--+ +-- --+ | |
| and |
| everybody, who can XXXX XXXXX |
| read this text XXXX XXXX XXXX |
| XXXX XXXX XXXX |
| from PiCSof XXXXXXXX XXXX XXXX |
| XXXXXXXX XX XXXXX XX |
| |
| |
+-------------------------------------------------COPYRIGHT 1996---+

Linc Family

Description Linc Family

These are harmless memory resident parasitic viruses. "Linc.228,318" are encrypted viruses.
They use different ways to install itself into the system memory. "Linc.196,228" copy themselves to the Interrupt Vectors Table, "Linc.307" allocates the memory by using DOS functions and patches the MCB fields, "Linc.318" stays memory resident by using Keep call (INT 27h).
Then they hook INT 21h and infect COM files that are executed. "Linc.196,228,307" write themselves to the end, and "Linc.318" writes itself to the beginning of the file.
The viruses contain the text strings:
"Linc.196": Winter
"Linc.228": Autumn
"Linc.307": 'The Waxwork Crew' proudly release their first virus 'aardvark'
"Linc.318": [Sleeping]

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



House In Brazil
Professional Seo Services
Herbal Colon Cleanse
Property For Sale Bled
Auto Future Technology

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com