Virus Database


Wally.1029

Description Wally.1029

It's a dangerous not memory resident parasitic encrypted virus. It searches for C:COMMAND.COM file and then for .COM-files of subdirectory tree if there's no C:COMMAND.COM file. The virus writes itself to the files ends. It erases CHKLST.CPS file. Depending on the system date and time it erases disk sectors and displays the message:
Virus Wally versao programa.Tente me encontrar.

Check other viruses! Be aware! Use Antiviral Software

Demiurg.3061

Description Demiurg.3061

It is a dangerous memory resident encrypted multipartite stealth virus. It writes itself to the end of COM and EXE files that are created on (copied to) floppy disks, and to the MBR of the hard drive.
While executing an infected file the virus traces INT 13h, 21h, 2Ah, hooks INT 13h and INT 2Ah, then it infects the MBR of the hard drive and stays memory resident. While loading from infected MBR the virus hooks INT 13h, 1Ch, waits for DOS loading process, and then hooks INT 2Ah.
To hook INT 13h the virus patches the DOS kernel in the HMA at fixed offsets. The virus writes to there INT CEh call (CDh CEh) and hooks INT CEh. These offsets are correct for DOS 6.x and may be not correct for other DOS versions. As a result the virus can halt the system. The virus has other bugs, and can halt the system while loading from infected MBR.
The virus INT 13h handler is used to call stealth routine only, and hide the infected MBR. By hooking INT 2Ah the virus receives the control from the DOS kernel, intercepts file accessing calls, and infects the files on the floppy disks only, and that are created and then closed or accessed with FindFirst/Next ASCII calls. While opening an infected file the virus disinfects it.
While opening the A-Dinf-°.°°° file the virus checks the system, and in some cases erases its code from the hard drive. While loading from such disk the system halts.
The virus contains the text strings in Russian and:
Demiurg.
LORD

Democracy.3670

Description Democracy.3670

These are not dangerous memory resident parasitic viruses. They hook INT 1, 3, 16h, 21h, 28h, 2Fh and write themselves to the end of COM- and EXE-files on their execution or searching. They contain the internal text "Democracy". Sometimes they display some messages.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Fun Games
Pkv Vergleich Online
Sms Signaler Short Message Service
Bilstyling
Utah Search Engine Optimization

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com