Weird.1800
Description Weird.1800
It is not a dangerous nonmemory resident encrypted parasitic virus. It searches for .COM files, then writes itself to the end of the file. While infecting files the virus temporary renames them with TXT file name extension. The virus deletes the anti-virus data files: CHKLIST.MS, CHKLIST.CPS, ANTI-VIR.DAT. The virus creates/overwrites the C:DOSMSD.INI file with the text: You are now looking at the name/passwords of your network! Greetings, ThE wEiRd GeNiUs. Check your MSD.INI once in a while!
The virus then leaves a memory resident program that hooks INT 16h, 21h and when LOGIN is executed, hooks keys that are entered and stores it in C:DOSMSD.INI file. On 1st of any month the virus prints that file. The virus also contains the text: LOGIN PRN PATH=*.COM .TXT TBDRVX COMM CHKLIST.MS CHKLIST.CPS ANTI-VIR.DAT GETPASS! V3.X
Check other viruses! Be aware! Use Antiviral Software
EMS.427
Description EMS.427
It's a harmless memory resident parasitic virus. It copies itself into EMS memory and Interrupt Vectors Table, hooks INT 21h and writes itself to the end of COM-files that are executed. It contains the internal text string: "EMMXXXX0".
Enculator.1089
Description Enculator.1089
It's a not dangerous memory resident parasitic virus. On execution of the infected file it hits the COMMAND.COM file and returns control to the host program. On execution of infected COMMAND.COM it searches for COM- and EXE-files and writes itself to their end. Then it hooks INT 21h and hits the executable files that are accessed. It searches and deletes the files SMARTCHK.* and CHKLIST.*. It contains the internal text strings: ENCULATOR III COMSPEC= *.COM *.EXE SMARTCHK.* CHKLIST.* COMMAND.COM
Enculator.Turbo.1366 It's a dangerous not memory resident parasitic virus. It searches for COM- and EXE-files and writes itself tp their ends. Sometimes it reboots the computer. It contains the internal text string: Sorry, I think this is a Brain Faillure !!!! TV II (C) Turbo Power 94
|