Win95.Lud family
Description Win95.Lud family
This virus looks for a "cave" between first and second file sections and writes itself to there (see "Win95.CIH" virus). If there is no enough space in this cave, the virus does not infect the file. As a result of infection method, the virus does not increase the size of files while infecting them. The virus contains the text string: HILLARY
Lud.Jez This virus infects the files by using one of standard ways: it creates new section at the end of the file and writes itself to there. This section is named ".jezzy". The virus also contains the text: The Jezebel Virus
Lud.Jadis, Lud.Yel These viruses use more sophisticated method: while infecting a file they scan it for executable section, move all other sections down to allocate a "cave" of necessary size, write themselves to there and fix parameters of all modified sections: size, offset in file, e.t.c. The viruses also pay special attention for sections that contain relocation tables, export and import data tables. The viruses fix all necessary fields in them. "Lud.Jadis" also scans for PE EXE files in subdirectory tree, not only in the current directory. It contains a bug: corrupts the Import Address table. This virus contains the text string: Your computer has eaten my turkish delight! - Jadis, Queen of Charn.
Check other viruses! Be aware! Use Antiviral Software
Hafen.781
Description Hafen.781
These are not dangerous nonmemory resident parasitic viruses. They search for .EXE files of the subdirectory tree, and write themselves to the end of the file. "Hafen.1640,1641,1689" contain the decrypted body of "Ambulance" virus, and infect .COM files with this sample (drop the virus). "Hafen.809" decrypts and displays the message: Hafenstraße bleibt !
"Hafen.781" decrypts and prints to the printer the message: Kilroy was here - (C) 1991, VDV.
"Hafen.818" creates the files with the random names, these files contain the text: Hafenstraße bleibt !
"Hafen.1191" manifests itself with a moving picture:
Haharin
Description Haharin
It is a very dangerous memory resident boot virus. It hooks INT 13h and writes itself to the MBR of the hard drives and boot sector of floppy disks. Depending on its counter the virus erases disk sectors and displays the message: Haharin is not dead !
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|