Win95.Sab
Description Win95.Sab
These are nonmemory reisdent parasitic Win9x viruses. They replicate under Win95/98 only and infect PE executable files. When an infected file is executed, the virus searches for PE EXE files in the current directory only, then writes itself to the end of the file. To access disk files the viruses scan Windows kernel, locate a "gate routine" to DOS functions (INT 21h) and then use that "gate" to call old-style DOS functions: file find, open, read and write. This method is valid for Win9x kernel only, and the viruses fail to spread under WinNT. Sab.512 The virus marks the infected files with the "w512" stamp in the PE header to avoid reinfection. The virus has bugs and often corrupts files while infecting them. Overall, it is a Silly and Buggy virus, that it why it was named "Sab" (that was the first known virus version, and that name was kept whole family). Sab.753 This virus seems to be bugs-free, and infected files stays not corrupted. The virus does not manifest itself in any way. It contains the text strings: When the hour comes you'll have to pay Pay with your lives, Watch your backs! It's time for holocaust, holocaust, HOLOCAUST 2000! Win9x.H0l0caust 2000! Brought to you from System33 security! Copyright (c) DemenTed of System33 security
Check other viruses! Be aware! Use Antiviral Software
Antidaf.561
Description Antidaf.561
It's avery dangerous not memory resident encrypted parasitic infector. It searches for .COM-files and infects them by a standard manner. In November on every Monday it types the message and erases FAT sectors of current drive: The Anti-DAF virus DAF-TRUCKS Eindhoven Hugo vd Goeslaan 1 Postbus 90063 5600 PR Eindhoven, The Netherlands DAF sucksall (c) 1992 Dark Helmet & The Virus Research Centre
AntiEta.5315
Description AntiEta.5315
It is not a dangerous memory resident parasitic polymorphic virus. It writes itself to the end of COM and EXE files and uses several level of encryption in infected files and its TSR copy. On July 12th the virus displays an image of a palm and the text: "ANTI-ETA". The virus also contains the text: << ANTI-ETA ViRuS Bio.Coded By GriYo / 29A >>
When an infected file is executed, the virus hooks INT 21h and stays memory resident. It then intercepts file execution and opening, stores their names and infects them when they are closed or program is terminated. The virus checks the file names and does not infect TBAV, SCAN, WIN and COMMAND.COM. On changing current directory the virus depending on its random counter drops a random named infected COM file. The virus also deletes the anti-virus data files, if they exist: ANTI-VIR.DAT, CHKLIST.MS.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Atlas Do ćwiczeń Discover New Zealand 24 H Truck Service Ltd Uk Filial Sverige
|