Virus Database


Win32.Henky.Rotten.1408

Description Win32.Henky.Rotten.1408

This is a harmless Win32 virus, 1408 bytes in size, written in assembler. It searches the currect directory for executable files and infects them by writing itself to the last section.
It contains the following text string:
W32/ROTTEN1408 by HenKy

Check other viruses! Be aware! Use Antiviral Software

Sepultura.242

Description Sepultura.242

It is a harmless memory resident parasitic virus. It copies itself to the Interrupt Vectors Table, hooks INT 21h and writes itself to the end of COM files that are executed. It contains the text string:
[242] Sepultura

Serbu family

Description Serbu family

These are not dangerous memory resident encrypted parasitic viruses. They use several levels of anti-debugging tricks in installation routine as well as in interrupt handlers. They write themselves to the end of COM and EXE files that are executed or opened, as well as to the end of .GIF and .JPG files (!!).
When an infected file is executed, the virus decrypts itself by using INT 1 and INT 3 hooks, then allocates block of DOS memory, copies itself to there, traces INT 21h, 2F and hooks them. To hook INT 2Fh the virus patches the DOS kernel.
Depending on the system date the viruses display the rectangle:
XXXXXXXX
XXXXXXXX

"Serbu.3493" displays the text:
.. A_C_O: Dirgantara Jaya ..

The viruses also contain the text strings:
"Serbu.3493": R-SERBU-1 (c)09-16H Emhaka
"Serbu.3493": -SERBU-

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Wind Energy
Food
Mexico Resorts
Car Insurance Company

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com