Virus Database


Win32.Maya.4106

Description Win32.Maya.4106

To get access to Windows functions the virus scans KERNEL32 export table, gets the GetProcAddress function address and then by using this value gets addresses of necessary functions:
KERNEL32.DLL:

GetModuleHandleA GetProcAddress CreateFileA WriteFile GetFileSize
CreateFileMappingA MapViewOfFile UnmapViewOfFile CloseHandle
FindFirstFileA FindNextFileA FindClose SetFilePointer SetEndOfFile
GetCurrentDirectoryA SetCurrentDirectoryA GetFileAttributesA
SetFileAttributesA GetSystemTime GetWindowsDirectoryA

USER32.DLL and ADVAPI32.DLL:

RegOpenKeyExA RegSetValueExA MessageBoxA SystemParametersInfoA

The "per-process resident" code of the virus scans current (host) process imports table and hooks following Windows file access functions, if the process imports them:
MoveFileA CopyFileA CreateFileA DeleteFileA SetFileAttributesA
GetFileAttributesA GetFullPathNameA CreateProcessA

The virus also contains the text strings:
To Aparna S. : Forever in love with youall
AYAM
IAHS
Control PanelDesktop
TileWallpaper
WallpaperStyle
SLAM.BMP

Check other viruses! Be aware! Use Antiviral Software

Apocalipse.1685

Description Apocalipse.1685

It is a dangerous memory resident encrypted parasitic virus. It traces INT 13h, 21h, hooks INT 21h and writes itself to the end of COM and EXE files that are executed. While installing into the system memory it also infects the C:DOSMODE.COM file.
The virus writes the counter into hard drive sector and increases that counter each time the virus installs itself into the memory. After 100 installation the virus corrupts CMOS and MBR of the hard drive, and displays:
Apocalipse 2.0 por M.A.C.
Isto é um vírus - afaste-se do computador, sen¦o constipa-se !
Boa sorte nas reparaç_es - nada está perdidoall
Também, andavas a trabalhar demais - aproveita para descansar !
Lembra-te: coisas destas só ajudam a formar caracter - n¦o,
n¦o precisas de agradecer, é um prazer ajudar...
Voltarei...
Preme uma tecla

Apokalipsa.1167

Description Apokalipsa.1167

It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are executed. In year 2000 the virus decrypts and displays the messages:
Wellcome to 21st century.
Author (Martin Zdila - MATOSoft) wish you no viruses in your computer
(except me - APOKALIPSA). I (virus) was born in SLOVAKIA in 1997/98.
Don't panic, I am harmless virus what is waiting for APOKALIPSA.
Press any key to continue.
Oh my God allAPOKALIPSA is here !!!
ALL DATA ON YOUR DISK ARE DESTROYED, FOREVER !
... ha ha ha. I got you! Great
joke, isn't it ?!

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Sakkas PlattsÄttning
IPO BYGG VENT SMIDE
RingÖns Bilelektriska Aktiebolag
P & B BilvÅrdscenter Aktiebolag
HOMUNCULUS FRISKVÅRD

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com