Virus Database


Win.Pin

Description Win.Pin

This is a very dangerous memory resident parasitic Win16 virus. It infects Win16 NE EXE files (NewExe) and DOS EXE files. It is polymorphic in both Win16 NE and DOS EXE files. While infecting NE files, the virus creates a new section at the end of a file, encrypts and writes its code there, then modifies the necessary NE header fields. While infecting DOS EXE files, the virus writes its code to the end of the file, and modifies the DOS EXE header. The virus infection routine is buggy, and in some cases corrupts NE EXE files.
While infecting a file, the virus also checks the system date and time, and starting from the 16th of any month, depending on the system seconds counter, tries to erase data on the A: drive.
To stay "memory resident," the virus drops the VxD module that is the main part of its code. This module is dropped to the Windows system directory with the WINP16.386 name, and the virus then registers it in the SYSTEM.INI file in the [386Enh] section to force Windows to load a virus' VxD module upon each booting. The modified entry in SYSTEM.INI file appears as follows:
[386Enh]
device=winp16.386

When Windows loads this VxD module, the virus memory installation routine takes control. It hooks the INT 21h chain (DOS functions), intercepts file execution and upon any file start, searches for EXE files in the current directory and infects them. The virus checks the file names and does not infect the following files: APV.EXE (mistyped AVP.EXE?), SCAN*.EXE, TBAV*.EXE, DRWE*.EXE, AIDS*.EXE, KRNL*.EXE, WIN3*.EXE, and VICT*.EXE.
The virus' "resident" mode works under both Win16 and Win9x, so the virus is able to infect not only Win16 system, but Win9x also, and affect NE EXE files in Win9x directories.

Check other viruses! Be aware! Use Antiviral Software

BetaBoys Family

Description BetaBoys Family

These are parasitic viruses which infect COM-files at their ends.
BetaBoys.441
It's a harmless not memory resident virus. It searches for the .COM-files and infects them. It does not manifests itself, it contains the internal text strings:
-+( Severe Head-Ache Virus V2.oo )+-
Created by The Vile One & MaZ
Copyright (c)1992 The BetaBoys Development Corp.
-Sweden 04/19/92-

BetaBoys.450
It's a not dangerous memory resident virus. It copies itself into DOS system area, hooks INT 21h and hits .COM-files are executed. On execution of SCAN.EXE file the virus displays the message:
THE WORLD WiLL NEVER FORGETT US! -BetaBoys-

It contains the internal text also:
Blood Rage (c)1992 The BetaBoys

BetaBoys.459
It's a dangerous not memory resident virus. It searches for the .COM-files and infects them. It erases the disk sectors and deletes the files
c:autoexec.bat
c:config.sys
windowswin.com

It contains the text strings:
*.com C:Command.Com C:Autoexec.Bat C:Config.Sys windowswin.com
Why Windows (c)1992 MaZ / BetaBoys B.B

BetaBoys.457,538
These are dangerous not memory resident viruses. They search for .COM-files and infect them. On May, 12th and February, 25th they erase the disk C:, D: and E: sectors. "BetaBoys.538" is a encrypted virus. It contains the text strings:
*.COM
:+:+ The Data Molester Virus V1.oo +:+:
(c)1992 MaZ & The Vile One / The BetaBoys Development Corporation.

"BetaBoys.457" contains the text:
*.COM
-+( Severe Head-Ache Virus V2.oo )+-
Created by The Vile One & MaZ
Copyright (c)1992 The BetaBoys Development Corp.
-Sweden 04/19/92-

BetaBoys.575,615
These are dangerous memory resident encrypted viruses. On execution they copy themselves into the memory at the address 9000:0100 without MCB correction. It can cause the dangerous consequences. Then the viruses hook INT 21h and hit COM-files on their execution. They contain the internal text strings: "BetaBoys.575" -
Mexican Mud (c)1992 MaZ
The BetaBoys Development Corp.
+Sweden+

"BetaBoys.615" -
DEATH RATTLE V1.OO
(c)1992 The BetaBoys Development Corp.
+S+W+E+D+E+N+

Beware.442.a

Description Beware.442.a

This is a very dangerous non memory-resident virus. It hits .COM-files by standard way in the current directory. On Monday that falls on the 1st of any month the virus erases some sectors on floppies. It also contains text: "BEWARE ME - 0.01, Copr (c) DarkGraveSoft - Moscow 1990".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Download Games
Bowtrol Colon Cleanser
Dell Battery 53 Whr
Colon Cleansing
Kryssningar

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com