Win32.Oporto.3076
Description Win32.Oporto.3076
This is relatively harmless, per-process memory resident Windows virus. It infects Windows executable files only (PE EXE). While infecting, the virus increases the size of last file section, writes its code to there and modifies necessary fields in the PE header. To gain control when an infected file is executed, the virus writes a short "Jump-Virus" routine to the program's start-up routine. The virus does not modify the "program entry point" address. When an infected file is executed, the virus searches for PE EXE files in the current directory, then in the Windows or Windows system directory, and infects them. The virus then hooks fifteen Windows file-access functions (file searching, opening, etc.), stays in the Windows memory as a part of the host-file code, and when hooked functions are executed, the virus searches for PE EXE files on a disk and infects them. The virus is able to hook the Windows functions only in case where the host program uses them (imports them from a Windows kernel). The "life-time" of a resident-virus copy depends on the host program run: when it is terminated, the resident virus code is terminated too. The virus deletes the anti-virus data file ANTI-VIR.DAT. On September 24th, the virus displays the following MessageBox and halts the system: TOTILIX Presentsall This >TOTILIX< Virus was assembled at the city of Oporto Portugal! gas_par@hotmail.com (c) 1999 G@SP@R aka Sexus
Check other viruses! Be aware! Use Antiviral Software
Maverick family
Description Maverick family
These are very dangerous memory resident polymorphic parasitic viruses. They trace and hook INT 21h, then it write themselves to the end of COM and EXE files that are accessed. Depending on the system date "Maverick.1536" erases the disk sectors. It contains the text string: (c) ETERNAL MAVERICK. Kiev Computer Virus Club 1994.
If month number plus one is equal to day number (February 1st, March 2nd, all) "Maverick.2048" sets INT 4 (Overflow) to INT 13h, that may corrupt data on disk. If month number plus two is equal to day number, this virus displays the message and halts the computer: +--------------------------------+ | +----------------------------+ | | | LETS REST UNTIL TOMORROW ! | | | +----------------------------+ | | (c) ETERNAL MAVERICK 1995. | +--------------------------------+ Press RESET to continue...
Maverick.3584 It is a dangerous memory resident polymorphic and stealth parasitic virus. It hooks INT 21h and writes itself to the end of COM, EXE, SYS and OVL files that are accessed. The virus does not infect files with names that contain the sub-strings: PRO, SCA, EXT, WEB, COM, WIN. The virus searches in root directories of all available disks for files that have 6th symbol of name the same as disk letter, and deletes them. The virus contains the text string: Universe (c) Eternal Maverick
Maximum.1198
Description Maximum.1198
It is not a dangerous nonmemory resident parasitic virus. It searches for COM files, then writes itself to the end of the file. Depending on the system timer the virus decrypts and displays the message: Radio MAXIMUM virus ver.1.0 beta (c) 1995 D&M Software. Soall tell me, what is the frequency of Radio MAXIMUM?
and waits for "103.7" input. In case of correct answer, the virus displays: Right! Radio MAXIMUM - BEST Radio...
and returns to the host program, in another case the virus displays: Error! Now restarting...
and reboots the computer. The virus also contains the text string: :D&M.SYS COMMAND.IBMBIO.IBMDOS.DOS.PATH=
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|