Virus Database


BlackFlash.813

Description BlackFlash.813

It is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are executed. The virus does not infect files: TB*, SC*, KR*, WI*, F-* (anti-virus programs and Windows). The virus has bugs and may corrupt files while infecting them, or halt the system while installing memory resident. The virus contains the text strings:
G:LoGiNLoGiN.eXe
FAIRGROUND (c) BlackFlash!

Check other viruses! Be aware! Use Antiviral Software

Sayha.4000

Description Sayha.4000

It is not a dangerous(?) memory resident parasitic encrypted virus. It hooks INT 16h, 21h and writes itself to the end of COM and EXE files that are accessed. It contains the text string:
SW Error V2f Sayha Watpu

and displays the message:
Sayha Watru

SayNay Family

Description SayNay Family

These are not dangerous nonmemory resident parasitic viruses. They search for .COM files, then write themselves to the end of the file.
These viruses drop their source assembler code into ASM file. To do that the viruses contain this source code in their bodies in encrypted form, and that is why the length of the virus is more than 5K.
To drop that code the virus checks the command line for "NAY" argument. If that argument is found, the virus displays the message:
Magic! ;)

and creates the SAYNAY.ASM and SAYNAY.BAT files. Then the virus writes the source code to the SAYNAY.ASM file, and writes the strings:
TAsm /M2 SayNay.Asm
TLink /T SayNay.Obj
Copy /B SayNay.Com+SayNay.Asm

to the SAYNAY.BAT file. As a result there are two files - the former contains virus' source texts, and the letter contains instructions how to compile the source text and build the virus. Being executed BAT file runs Assembler and Linker to make the "intermediate" virus code that contains the binary code, but not the source text. Then the virus appends the source text to binary code by COPY command, and the result file contains the virus with its source text in not encrypted form. Being executed the virus encrypts that source text, searches and infects .COM files.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Bygg-allt
Bildeve Aktiebolag
Carros Vvs O Fastighetsservice
Extrackta Nordic Ab
Enter Telecom Group Etcg Ab

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com