Virus Database


UVR.3919

Description UVR.3919

It's a dangerous memory resident parasitic virus. On execution of infected file it writes the string
C:UVR.COM

at the beginning of C:AUTOEXEC.BAT file. Then the virus creates C:UVR.COM file and writes itself into there. On execution of that dropper file (i.e. on loading with modified AUTOEXEC.BAT) the virus hooks INT 21h and writes itself at the end of COM-files are executed or opened.
On execution of dropper file under already infected system, the virus displays:
UVR Already installed.

Before infection the virus disinfect the files infected with some parasitic viruses. If some program tries disinfect the file infected with "UVR" virus, it drops "Trivial.59" overwriting virus into the C:PORNO file. The virus deletes the files *.CPS and *._NO on accessing to them. It also creates the file C:C:\__ with two strings inside:
[Note "_" = ASCII 251]
Hai sbagliato!
-U.Vr-

On March, 19th the virus displays:
+-------------------+
¦ Vietato FUMARE! ¦
+-------------------+

then it hooks INT 10h and manifests itself with different video effects: on displaying the text strings it changes the case of characters, changes the cursor characteristics, and so on.
That virus contains the encrypted internal strings also:
- U.Vr, Professional version -
Non riuscirai MAI a sapere tutto quello che sono in grado di fare
MARZO 1993

Check other viruses! Be aware! Use Antiviral Software

Murcia.4651

Description Murcia.4651

It is not a dangerous memory resident partly encrypted parasitic virus. Being executed it searches for .COM files (except COMMAND.COM) in the subdirectory tree, then writes itself to the beginning of the file. The virus searches for the FLOWEROF.MAY file, and terminates the infection routine if that file is found. Next the virus hooks INT 8, 21h, stays memory resident, and when any file is executed, the virus searches for .COM files and infects them in the same way as described above.
Two months after infecting a computer the virus manifests itself in several ways. First, it creates the MURCIA!!.nnn file, where 'nnn' is the internal virus counter, then writes the text string to that file:
MURCIA (SPAIN): THE BEST PLACE IN THE WORLD!
WHERE THE PEOPLE MAKES VIRUSES FOR YOUR COMPUTER!
NOW, IN SPANISH:
¿SABES LO FACIL QUE RESULTARIA BORRARTE TODOS
LOS FICHEROS DEL DISCO? O MEJOR AUN: FORMATEARLO.
QUE PASES UN FELIZ DIA.

Then the virus manifests itself with a video and sound effects. The virus also contains the text strings:
BOYA_PARA_MOV
FLOWEROF.MAY COMMAND.COM MURCIA!!.003

Murderer.3670

Description Murderer.3670

It is a dangerous memory resident parasitic virus. It hooks INT 5, 8, 13h, 17h, 21h. On DOS calls CloseFile it searches and infects .COM and .EXE files. It writes itself to the beginning of .COM files, .EXE files are infected by companion manner.
That virus erases the disk sectors. On July, 3rd it displays the messages and plays a tune, the virus also prints the text:
To the human:
The emperor of darkness "Satan" has came back from hell, and he will destroy
the world, all human will be take to the horrendous darkness. But one man who
can fight with Satan, "Son of brightness" has born. He will lead us to fight
with Satan, and kick him back to the hell. So, hurry up, go to Taiwan to find
our rescuer ==> Chinq-shyang Lay. << All augur >>

It also contains the text strings:
<<< MURDERER Version 1.44 >>>
IBMBIO.COM
IBMDOS.COM
COMMAND.COM
SHEAU-YN.LIN
Bad command or file name

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Finance Business Online
Order Provillus
South Park Kenny Cartman Kyle Towli
Mahjongg
Mp3 Store Online

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com