Win32.Damm.1537
Description Win32.Damm.1537
This is a benign memory resident parasitic Windows virus. The virus uses Win98 specific calls and is able to spread only under Win98. To remain in the memory resident, the virus switches itself to kernel mode by using Win98 kernel functions, hooks the file access functions (IFS) and infects PE EXE files that are opened, renamed or when file attributes are accessed. While infecting a file, the virus writes itself to the end of the file. The virus uses anti-debugging tricks and seems to disable Windows debuggers. The virus also looks for several anti-virus monitors installed, and disables them by patching their code. The virus also checks file names before infecting and does not affect anti-virus programs and some utilities. The virus detects them by comparing a file name with a set of strings: AVP _AVP NAV TB F- WEB PAV GUARDDOG DRW SPIDER DSAV NOD MTX MATRIX WINICE FDISK SCAN DEFRAG On 1st of each month, the virus removes the Desktop icons with the registry key: HKCUSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer NoDesktop = 1 The virus also contains the "copyright" text strings: DAMMiT by ULTRAS [MATRiX] (c) 2000
Check other viruses! Be aware! Use Antiviral Software
Bleah.c
Description Bleah.c
This is a harmless memory resident encrypted boot virus. It infects the MBR of the hard drive and boot sector of floppy disks. While loading from infected disk it decreases the size of system memory (the word at address 0000:0413), copies itself to there, hooks INT 8 (timer), waits for DOS loading process, then restores the size of system memory and hooks INT 13h to infect the disks. As a result, the virus places itself to the block of system memory that is cut, but it does not change the total size of conventional memory.
Blind.549
Description Blind.549
It is a dangerous nonmemory resident parasitic virus. It searches for .COM files (except COMMAND.COM) in the current directory, then in directories that are marked in PATH=, then writes itself to the end of the file. The virus has bugs and in some cases corrupt files while infecting them. The virus contains the text strings: =Blind Guardian 1995= PATH=*.COM COMMAND.COM
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|