Bishop.2855
Description Bishop.2855
These are dangerous not memory resident overwriting polymorphic viruses. They search for .COM-files and overwrite them. These viruses use several levels of decryption, some parts of code and data are encrypted six or more times. These viruses use several anti-debugging tricks. They contain the internal text strings and sometimes display some of them: "Bishop.2855": STOP HERE! CULO We are waiting for.. A mutant BISHOP in this program 21-3-93, milan-PARMA : 0-1. *.COM -BISHOP-
"Bishop.4517": WHY DEBUGGER? PARMA CAMPIONE !!!!!!!! ANOTHER YEAR A mutant ROOK in this program *.COM - UAH UAH UAH! Non puoi fregare ROOK come fregasti BISHOP! - - ROOK - The ROOK virus !!! Understand? DECEMBER VERSION A variant of the DECEMBER VERSION +---+-----------------------+---+ ƒ R ƒ n ƒ b ƒ q ƒ k ƒ b ƒ n ƒ R ƒ +---+---+---+---+---+---+---+---+ ƒ p ƒ p ƒ p ƒ p ƒ p ƒ p ƒ p ƒ p ƒ +---+---+---+---+---+---+---+---ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ +---+---+---+---+---+---+---+---ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ +---+---+---+---+---+---+---+---ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ +---+---+---+---+---+---+---+---ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ ƒ +---+---+---+---+---+---+---+---ƒ ƒ p ƒ p ƒ p ƒ p ƒ p ƒ p ƒ p ƒ p ƒ +---+---+---+---+---+---+---+---+ ƒ R ƒ n ƒ b ƒ q ƒ k ƒ b ƒ n ƒ R ƒ +---+-----------------------+---+
Check other viruses! Be aware! Use Antiviral Software
Sauron.1088
Description Sauron.1088
This is a dangerous memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of .EXE files that are executed. It contains the text string "VIRCLEANSCANCPAVNAV", and does not infect files with the names from that string. In March, this virus erases the hard drive sectors and displays the following message: Sauron is not dead.
Sayha.4000
Description Sayha.4000
It is not a dangerous(?) memory resident parasitic encrypted virus. It hooks INT 16h, 21h and writes itself to the end of COM and EXE files that are accessed. It contains the text string: SW Error V2f Sayha Watpu
and displays the message: Sayha Watru
|