Virus Database


Win32.Apparition

Description Win32.Apparition

This is "memory resident" Windows32 (Windows95/NT) parasitic infector. It looks as the "Win.Apparition" Windows virus that was rewritten for Windows32 - it is of the same structure (code, compressed data and so on), it uses similar algorithm of installation, infection and mutation and so on. The differences are: this virus is written in C (Windows virus was written in Pascal), it has no visible window, it has other text strings and displays other MessageBoxes.
In similar way as Windows version, this virus corrupts files while infecting them - it looks for C/Pascal subroutines header and overwrites them with FFh,FFh,xxh bytes (xxh - random byte). When this code receives control, the system generates exception. The virus intercepts it and fixes the problem. As a result, A) infected files do work under infected system, but do not after disinfection; B) this is impossible to guarantee 100% disinfection ever after fixing these patched blocks. As a result, the infected files have to be erased.

Check other viruses! Be aware! Use Antiviral Software

AntiSabados.815

Description AntiSabados.815

It's a not dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself at the end of COM-files that are executed. Sometimes it reboots the computer. It contains the internal text string:
Virus ANTI-SABADOS 1.2 Echo por Dicker.

Antiscan.508

Description Antiscan.508

This is a dangerous, non-memory resident virus. It searches for *.G?? files and deletes them. It creates a C:SCAN.COM file, and writes itself into this file. Upon infection, it displays the following: "Shouldn't oughta be looking at nasty shit".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com