Win.Pin
Description Win.Pin
This is a very dangerous memory resident parasitic Win16 virus. It infects Win16 NE EXE files (NewExe) and DOS EXE files. It is polymorphic in both Win16 NE and DOS EXE files. While infecting NE files, the virus creates a new section at the end of a file, encrypts and writes its code there, then modifies the necessary NE header fields. While infecting DOS EXE files, the virus writes its code to the end of the file, and modifies the DOS EXE header. The virus infection routine is buggy, and in some cases corrupts NE EXE files. While infecting a file, the virus also checks the system date and time, and starting from the 16th of any month, depending on the system seconds counter, tries to erase data on the A: drive. To stay "memory resident," the virus drops the VxD module that is the main part of its code. This module is dropped to the Windows system directory with the WINP16.386 name, and the virus then registers it in the SYSTEM.INI file in the [386Enh] section to force Windows to load a virus' VxD module upon each booting. The modified entry in SYSTEM.INI file appears as follows: [386Enh] device=winp16.386
When Windows loads this VxD module, the virus memory installation routine takes control. It hooks the INT 21h chain (DOS functions), intercepts file execution and upon any file start, searches for EXE files in the current directory and infects them. The virus checks the file names and does not infect the following files: APV.EXE (mistyped AVP.EXE?), SCAN*.EXE, TBAV*.EXE, DRWE*.EXE, AIDS*.EXE, KRNL*.EXE, WIN3*.EXE, and VICT*.EXE. The virus' "resident" mode works under both Win16 and Win9x, so the virus is able to infect not only Win16 system, but Win9x also, and affect NE EXE files in Win9x directories.
Check other viruses! Be aware! Use Antiviral Software
BetaBoys Family
Description BetaBoys Family
These are parasitic viruses which infect COM-files at their ends. BetaBoys.441 It's a harmless not memory resident virus. It searches for the .COM-files and infects them. It does not manifests itself, it contains the internal text strings: -+( Severe Head-Ache Virus V2.oo )+- Created by The Vile One & MaZ Copyright (c)1992 The BetaBoys Development Corp. -Sweden 04/19/92-
BetaBoys.450 It's a not dangerous memory resident virus. It copies itself into DOS system area, hooks INT 21h and hits .COM-files are executed. On execution of SCAN.EXE file the virus displays the message: THE WORLD WiLL NEVER FORGETT US! -BetaBoys-
It contains the internal text also: Blood Rage (c)1992 The BetaBoys
BetaBoys.459 It's a dangerous not memory resident virus. It searches for the .COM-files and infects them. It erases the disk sectors and deletes the files c:autoexec.bat c:config.sys windowswin.com
It contains the text strings: *.com C:Command.Com C:Autoexec.Bat C:Config.Sys windowswin.com Why Windows (c)1992 MaZ / BetaBoys B.B
BetaBoys.457,538 These are dangerous not memory resident viruses. They search for .COM-files and infect them. On May, 12th and February, 25th they erase the disk C:, D: and E: sectors. "BetaBoys.538" is a encrypted virus. It contains the text strings: *.COM :+:+ The Data Molester Virus V1.oo +:+: (c)1992 MaZ & The Vile One / The BetaBoys Development Corporation.
"BetaBoys.457" contains the text: *.COM -+( Severe Head-Ache Virus V2.oo )+- Created by The Vile One & MaZ Copyright (c)1992 The BetaBoys Development Corp. -Sweden 04/19/92-
BetaBoys.575,615 These are dangerous memory resident encrypted viruses. On execution they copy themselves into the memory at the address 9000:0100 without MCB correction. It can cause the dangerous consequences. Then the viruses hook INT 21h and hit COM-files on their execution. They contain the internal text strings: "BetaBoys.575" - Mexican Mud (c)1992 MaZ The BetaBoys Development Corp. +Sweden+
"BetaBoys.615" - DEATH RATTLE V1.OO (c)1992 The BetaBoys Development Corp. +S+W+E+D+E+N+
Beware.442.a
Description Beware.442.a
This is a very dangerous non memory-resident virus. It hits .COM-files by standard way in the current directory. On Monday that falls on the 1st of any month the virus erases some sectors on floppies. It also contains text: "BEWARE ME - 0.01, Copr (c) DarkGraveSoft - Moscow 1990".
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Download Games Bowtrol Colon Cleanser Dell Battery 53 Whr Colon Cleansing Kryssningar
|