Virus Database


Win95.Sab

Description Win95.Sab

These are nonmemory reisdent parasitic Win9x viruses. They replicate under Win95/98 only and infect PE executable files. When an infected file is executed, the virus searches for PE EXE files in the current directory only, then writes itself to the end of the file.
To access disk files the viruses scan Windows kernel, locate a "gate routine" to DOS functions (INT 21h) and then use that "gate" to call old-style DOS functions: file find, open, read and write. This method is valid for Win9x kernel only, and the viruses fail to spread under WinNT.
Sab.512
The virus marks the infected files with the "w512" stamp in the PE header to avoid reinfection. The virus has bugs and often corrupts files while infecting them. Overall, it is a Silly and Buggy virus, that it why it was named "Sab" (that was the first known virus version, and that name was kept whole family).
Sab.753
This virus seems to be bugs-free, and infected files stays not corrupted.
The virus does not manifest itself in any way. It contains the text strings:
When the hour comes you'll have to pay
Pay with your lives, Watch your backs!
It's time for holocaust, holocaust, HOLOCAUST 2000!
Win9x.H0l0caust 2000! Brought to you from System33 security!
Copyright (c) DemenTed of System33 security

Check other viruses! Be aware! Use Antiviral Software

Antidaf.561

Description Antidaf.561

It's avery dangerous not memory resident encrypted parasitic infector. It searches for .COM-files and infects them by a standard manner. In November on every Monday it types the message and erases FAT sectors of current drive:
The Anti-DAF virus
DAF-TRUCKS Eindhoven
Hugo vd Goeslaan 1
Postbus 90063
5600 PR Eindhoven, The Netherlands
DAF sucksall
(c) 1992 Dark Helmet & The Virus Research Centre

AntiEta.5315

Description AntiEta.5315

It is not a dangerous memory resident parasitic polymorphic virus. It writes itself to the end of COM and EXE files and uses several level of encryption in infected files and its TSR copy. On July 12th the virus displays an image of a palm and the text: "ANTI-ETA". The virus also contains the text:
<< ANTI-ETA ViRuS Bio.Coded By GriYo / 29A >>

When an infected file is executed, the virus hooks INT 21h and stays memory resident. It then intercepts file execution and opening, stores their names and infects them when they are closed or program is terminated. The virus checks the file names and does not infect TBAV, SCAN, WIN and COMMAND.COM. On changing current directory the virus depending on its random counter drops a random named infected COM file. The virus also deletes the anti-virus data files, if they exist: ANTI-VIR.DAT, CHKLIST.MS.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Atlas Do ćwiczeń
Discover New Zealand
24 H Truck Service Ltd Uk Filial Sverige

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com