Virus Database


WestUkrain.274

Description WestUkrain.274

It's a dangerous not memory resident parasitic virus. It searches for .COM-files and writes itself to their ends. Starting from the 25th generation the virus corrupts the files instead of infection. It contains the internal text strings:
*.COM
Western Ukraine

Check other viruses! Be aware! Use Antiviral Software

Nostardamus family

Description Nostardamus family

These are very dangerous memory resident polymorphic parasitic viruses. They hook 21h and writes itself to the end of COM and EXE files that are accessed.
Depending on the system timer and their internal counters these viruses also hook INT 10h, or INT 16h, or INT 1Ch (depending on the virus version), and manifest themselves by several effects: they corrupt the files, erase the disk sectors, change the keystrokes that are entered, display the message:
HOME RUN !!!

The viruses also display:
"Nostardamus.2247":
The NOSTARDAMUS-Erase (c) v2.1 beta
Formating disk C:
40Mb

"Nostardamus.2500,2560":
The NOSTARDAMUS-Erase (CopyLeft) Version 2.9 beta by Populizer
Formatting disk X: 40Mb

"Nostardamus.5995":
The NOSTARDAMUS.Maverick (CopyLeft) Version 3.2 ultra by Populizer
Formatting disk X: 40M

"Nostardamus.5995" also displays about 100 stupid messages in Russian and English:
Invalid user. Unknown error !
Good user - Dead user !!!
Insert new user and press ESC
I'm big RUSSIAN monstr !!
System error, invalid TC.EXE.
See you later all
Formatting disk C: y/y ?
Press CTRL-ALT-DEL ...
Crazy & Co. ltd.
Insert new baks into drive A:
(C) Porno C++ 3.1
(C) Trubo Pascacal 7.0
Virus detected, system halted

"Nostardamus.3072,3584" use INT 22h hook to wait the host program termination, hook INT 21h and install themselves memory resident. They are stealth viruses, while accessing to an infected file they disinfect it. They check the file name and do not infect several anti-virus programs. "Nostardamus.3072" is a harmless virus. It does not manifest itself.
"Nostardamus.3584" is a very dangerous virus, in some cases it searches for C:*.* files and deletes them. This virus checks the file name by using the strings:
COMEXEOVLOVR
PROSCAEXTWEB
ARJRARLHAZIP
COMWINCHK

and does not infect these files or disables its stealth routines.
These viruses also contain the strings:
"Nostardamus.3072.a": EMME v3.0. KILLER.
"Nostardamus.3072.b": Eternal Maverick Mutation Engine v3.0
Double Dragon !
"Nostardamus.3584": -=Unlimited Grief=-
Kiev'96
EMME 3
Killer
"Nostardamus.RunAway.2560":
Run away train never come back !
(c) Eternal Maverick. Stealth Group.

Nostardamus.3072.a

Description Nostardamus.3072.a

This is a harmless virus. It does not manifest itself.
It uses INT 22h hook to wait the host program termination, hooks INT 21h and installs itself memory resident. It's a stealth virus, while accessing to an infected file it disinfects it. It checks the file name and do not infect several anti-virus programs.
This virus also contains the string:
EMME v3.0. KILLER

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com