Virus Database


V.6000

Description V.6000

It is a dangerous memory resident polymorphic stealth multipartite virus. While executing an infected file or loading from infected floppy disk that virus writes itself to the MBR of the hard drive. The virus stays memory resident on loading from infected MBR only, it hooks INT 8, 13h, 17h, 1Ch, 20h, 21h, 25h, 26h, 27h and writes itself to the end of COM and EXE files that are accessed, or on the program termination. Depending on its internal counter the virus searches for the files and infects them. The virus checks the file names and does not infect the files:
COMMAND.COM, GDI.EXE, DOSX.EXE, WIN386.EXE, KRNL286.EXE, KRNL386.EXE,
USER.EXE, WSWAP.EXE, CHKDSK.EXE

On accessing to a floppy disk the virus writes itself to the boot sector. Depending on its internal counters and under debuggers the virus erases the CMOS and the hard drive sectors.
The virus uses a complex algorithm allowing the virus to stay memory resident after cold reboot and loading from a clean DOS floppy disk. On installation the virus stores the CMOS memory that keeps the information about floppy drives and sets that info to zero (i.e. the virus emulates situation when no floppy drives are installed). On accessing to disks the virus temporary restores the CMOS and then erases these fields again. On any (cold or warm) reboot the system checks the CMOS, does not detect the floppy disks and passes the control to the MBR of hard drive. As a result the virus in the MBR receives the control, installs itself into the memory and then passes the control to the floppy disk loader. As a result the virus stays memory resident after loading from a clean write-protected disk.

Check other viruses! Be aware! Use Antiviral Software

T-Rex.1800

Description T-Rex.1800

It is not a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. The virus does not infects the files: COMMAND, WIN and F-PROT. On 1st of January and June the virus displays:
--- +--+ ---+ ---+ ---+ +--+ +--+
¦ ¦ ¦ ¦- ¦- ¦--+ ¦ ¦ ¦ ¦
--- - - - ---+ - - - - +--+
Inferno Virus (c) 1996 T-Rex

It also contains the text strings:
* Inferno is unleashedall Goodluck !
The Inferno Virus : 1800 Bytes of Sheer Magic From T-Rex

T_Power family

Description T_Power family

These are dangerous memory resident encrypted parasitic viruses. They hook INT 1Ch, 21h, and on file opening, execution and creating these viruses search for COM and EXE files and write themselves to the end of the file. The viruses do not infect several anti-virus programs, they also search for some anti-virus data files and delete them. Depending on their internal counter "T_Power.Cowa" reboots the computer, "T_Power.Zarma" disables/enables the video refresh. The viruses contain the text strings:
OMSPEC=
*.COM *.EXE
SMART*.* CHK*.* ANTI-VIR.DAT *.VIR NAV_._*
SCAN F- VIR VSH AV .S BMB BMD TB IM IV

They also contain the strings:
"T_Power.Cowa": COWA-BUNGA VIRUS (C) 1994 by Turbo Power *** Claudia
Schieffer Lives !!!
"T_Power.Sodo": [Sodomizator/T.Power] Do you like me ?
"T_Power.Zarma": ZARMA-VIR by T.Power *** Claudia Schiffer Lives !!!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com