Virus Database


Uranus.2048

Description Uranus.2048

It is a harmless memory resident multipartite virus. It infects COM, EXE, NewEXE (NE) files and disk boot sectors. When an infected file is executed, the virus writes its code to the first hard drive track (unused sectors) and writes its loader to the boot sector of C: drive. The virus then returns to the host program.
When the system is loaded from infected disk, the virus hooks INT 13h, waits for DOS loading process, hooks INT 21h and writes itself to the end of COM, EXE and NewEXE (NE) files that are executed or accessed by FindFirst/Next ASCII DOS calls. When 1.4Mb floppy disks are accessed, the virus infects their boot sectors.
The virus checks the file names - it compares two last letters of file name with pairs of letters of the string:
ANOT86AVVPUSILEDOPNDLPGRPLRKYRRE

and does not infect these files (anti-viruses and utilities SCAN, F-PROT, KRNL386, NAV, AVP, FINDVIRUS, MSMAIL and so on).
The virus also contains the string:
Sailor_Uranus

Check other viruses! Be aware! Use Antiviral Software

Peasant.1243

Description Peasant.1243

This is a dangerous memory resident parasitic virus. When an infected EXE file is executed, the virus searches for a command interpreter (COMMAND.COM) by using the string "COMSPEC=", and overwrites it. The virus stores the part of the code that is overwritten into the unused sectors of the hard drive, then the virus returns control to the host program.
When an infected COMMAND.COM is executed, the virus reads its original code from the hard drive sectors, hooks INT 21h and returns control to COMMAND.COM. Then the virus writes itself to the end of EXE files that are accessed.
On Mondays, it disables the DOS functions SetDir, RemoveDir and ChangeDir; and when the files are deleted, it "hides" them with corresponding attributes, upon writing to files, the virus appends to them with the string:
"""NoImportRICE!"""

It displays the same string while terminating the programs. The virus also contains the text string:
(c)KoRea-PeaSant

Pebble

Description Pebble

It is a dangerous memory resident boot virus. It hooks INT 9, 13h and writes itself to the boot sector of floppy disks on reading from them. It infects the hard drive while loading from infected floppy. It saves the original MBR sector on the 7th hard drive sector and the original boot sector on the last root directory sector of a diskette. Because of an error while infecting floppy disks the virus corrupts the disk parameters table.
On entering keys (INT 9) the virus changes the color attribute of top-left character on the screen.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Online Jewelry Store
Palestine Phone Cards
Marketing Wyszukiwarkach
Seo

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com