Win32.HLLC.Vedex
Description Win32.HLLC.Vedex
Win32.HLLC.Vedex is a dangerous non-memory resident companion Win32 virus. The virus itself is a Windows PE EXE file about 45Kb in length, written in Delphi. It searches for .EXE files in the current directory and subdirectories and infects them. While infecting it renames victim files with the name '%FileName%vdx.dll', and replaces the victim with its own copy, for example:
NOTEPAD.EXE -> NOTEPADvdx.dll To return control to the host file, the virus copies the %FileName%vdx.dll file to %FileName%vdx.dll.EXE and executes it, for example:
NOTEPADvdx.dll -> NOTEPADvdx.dll.EXE The virus also creates the C:IOS.BAT file with a hidden attributes set, writes a trojan Batch program to this file and runs it. This trojan, when run increases its file length in an endless loop, and fills all the disk's free space.
Check other viruses! Be aware! Use Antiviral Software
AntiSkola.2111
Description AntiSkola.2111
It is a dangerous memory resident parasitic virus. It hooks INT 9, 21h and writes itself to the end of COM and EXE files that are executed. While infecting the COMMAND.COM file the virus patches its code at fixed offset and writes JMP-Virus instruction to there. That does work only for some COMMAND.COM version(s) and corrupts COMMAND.COM from other DOSes (including Win95). On keystrokes (INT 9) depending on the system timer the virus changes the data in keyboard buffer. Depending on the system timer the virus stops executing the TURBO.EXE and TPX.EXE files. Also depending on the system time the virus decrypts and displays the message (see below), plays a tune and halts the computer: Dobry den,predstavuje se Vam virus AntiSkola.Tento virus byl napsan pro demonstraci idealniho preziti viru ve skolnim prostredi.Doufam, ze se Vam bude libit. Moje podekovani patri zejmena : Firme Borland International Inc. za TurboAssembler a TurboDebugger Skole za to,ze mi umoznila nerusene programovat Firme Microsoft za "operacni system" MS-DOS,ktery byl koncipovan primo pro viry.Na prikladu WINDOWS 95 je jasne videt,ze se stale teto filozofie nevzavaji.Mozna by si meli neco precist o protected modu a preemtivnim multitaskingu. At zije SOSE v Brne na Obranske !!
AntiTrace.2122
Description AntiTrace.2122 It's a not dangerous memory resident parasitic virus. It hooks INT 21h and writes itself at the end of COM-files on their closing. On infected file opening it disinfects it. The virus uses anti-debugging tricks, on tracing of INT 21h it displays the message: +--------- Anti_Trace ----------+ ƒ ƒ ƒ Loading AntiVirus didn't find ƒ ƒ me yet. I'm so sorry! ƒ ƒ ƒ ƒ [ Continue ] ƒ +-------------------------------+ It contains the internal strings also: Anti_Trace Good Luck in Creating Antivirus. (C) 1993, AT Corp.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Antler Ballpoint Pens Cheap Calling Cards Mobiler - Noika Ericsson Ringsignal Chuck Norris Facts Viewsonic Viewpad 10
|