Virus Database


Win32.FunLove.4070

Description Win32.FunLove.4070

FunLove (aka Fun Loving Criminals) is a benign memory resident parasitic Win32 virus. It affects PE EXE files on local and network drives. Because of its network spreading ability, the virus can infect the local network from one infected workstation, in the case that the network access permission allows for the writing of this user.
The virus contains the following text strings:
~Fun Loving Criminal~

When an infected file is run, the virus creates a FLCSS.EXE file in the Windows system directory, writes its "pure" code to there and runs this file. This virus "dropper" (FLCSS.EXE file) has a Win32 PE format and is executed by the virus as a hidden Windows application (under Win9x) or as a service (under WinNT), and the infection routine takes control.
In case an error has occurred while creating the dropper file (when the virus is run from an infected file), the virus runs the infection routine from its example in the infected host file. The file searching and infection process is run in the background as a "thread," and as a result, the host program is executed with no "visible" delays.
The infection routine scans all local drives from C: till Z:, then looks for network resources, scans subdirectory trees there and infects PE files that have a .OCX, .SCR or .EXE name extension. While infecting a file, the virus writes its code to the end of the file to the last file section and patches its entry routine with a "JumpVirus" instruction. The virus checks file names and does not infect the files: ALER*, AMON*, _AVP*, AVP3*, AVPM*, F-PR*, NAVW*, SCAN*, SMSS*, DDHE*, DPLA*, MPLA*.
The virus is related to the Bolzano virus family and patches the NTLDR and WINNTSystem32 toskrnl.exe files in a similar way the "Bolzano" virus does. The patched files should be restored from backup.

Check other viruses! Be aware! Use Antiviral Software

Cannibal.1312

Description Cannibal.1312

Cannibal.1312 is a dangerous memory resident encrypted parasitic virus. It hooks INT 10h, 28h, 2Fh, 4Ah and on INT 10h, 28h calls infects the file which performs that call. On infection the virus writes itself at the end of the files. It contains the bug and corrupts .EXE-files on infection. It creates the file
C:VIRUS.$$$cannibal.max

and writes the text into it:
_______________________________________
MAX CANNIBAL vers.1.04
(c)93 PAVLOVO CITY
_______________________________________
"_" = non displayable character.

The virus displays that text on INT 4Ah calls. It also contains the internal text strings:
AIDS
Mad Max

Cantando.857

Description Cantando.857

It is a not dangerous not memory resident encrypted parasitic virus. It searches for COM-files (except COMMAND.COM) and writes itself at their ends. It deletes the CHKLIST.MS files, displays the message:
* CaN_TaN_Do_v01 : "Onkos täällä kilttejä lapsia?-)" *

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Bondenbar
PeÖs - Bygg
Ab Donton
Eliasson, Tomas
Mekonomen Segeltorp Aktiebolag

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com