Virus Database


Win95.Uwaga

Description Win95.Uwaga

This is a relatively harmless, non-memory resident parasitic Win95 virus. It searches for PE EXE files, then writes itself to the end of the file, increases the size of the last section, writes its code there and modifies the entry-point address. To gain access to the Windows file access function, the virus scans Win95 Kernel32 internal formats. To detect previously infected files, the virus compares section names with its own section name "BEDM." The virus also does not infect files compressed with the Petite PE files compression utility.
On February 25th, the virus displays the following MessageBox:
Rafa+ !
Wszystkiego najlepszego z okazji urodzin !

On the 13th of any month, it displays the following MessageBox and exits Windows:
Uwaga !Aby uruchomiæ ten program musisz zresetowaæ komputer !

The virus also contains a text that contains names of functions and libraries used by the virus:
KERNEL32.DLL USER32.DLL
GetModuleHandleA GetProcAddress FindFirstFileA FindNextFileA
SetCurrentDirectoryA GetCurrentDirectoryA CreateFileA ReadFile WriteFile
SetFilePointer CloseHandle GetSystemTime LoadLibraryA MessageBoxA
ExitWindowsEx

Check other viruses! Be aware! Use Antiviral Software

Murcia.4651

Description Murcia.4651

It is not a dangerous memory resident partly encrypted parasitic virus. Being executed it searches for .COM files (except COMMAND.COM) in the subdirectory tree, then writes itself to the beginning of the file. The virus searches for the FLOWEROF.MAY file, and terminates the infection routine if that file is found. Next the virus hooks INT 8, 21h, stays memory resident, and when any file is executed, the virus searches for .COM files and infects them in the same way as described above.
Two months after infecting a computer the virus manifests itself in several ways. First, it creates the MURCIA!!.nnn file, where 'nnn' is the internal virus counter, then writes the text string to that file:
MURCIA (SPAIN): THE BEST PLACE IN THE WORLD!
WHERE THE PEOPLE MAKES VIRUSES FOR YOUR COMPUTER!
NOW, IN SPANISH:
¿SABES LO FACIL QUE RESULTARIA BORRARTE TODOS
LOS FICHEROS DEL DISCO? O MEJOR AUN: FORMATEARLO.
QUE PASES UN FELIZ DIA.

Then the virus manifests itself with a video and sound effects. The virus also contains the text strings:
BOYA_PARA_MOV
FLOWEROF.MAY COMMAND.COM MURCIA!!.003

Murderer.3670

Description Murderer.3670

It is a dangerous memory resident parasitic virus. It hooks INT 5, 8, 13h, 17h, 21h. On DOS calls CloseFile it searches and infects .COM and .EXE files. It writes itself to the beginning of .COM files, .EXE files are infected by companion manner.
That virus erases the disk sectors. On July, 3rd it displays the messages and plays a tune, the virus also prints the text:
To the human:
The emperor of darkness "Satan" has came back from hell, and he will destroy
the world, all human will be take to the horrendous darkness. But one man who
can fight with Satan, "Son of brightness" has born. He will lead us to fight
with Satan, and kick him back to the hell. So, hurry up, go to Taiwan to find
our rescuer ==> Chinq-shyang Lay. << All augur >>

It also contains the text strings:
<<< MURDERER Version 1.44 >>>
IBMBIO.COM
IBMDOS.COM
COMMAND.COM
SHEAU-YN.LIN
Bad command or file name

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Buy Ukraine Nude Photos
Rca Ieftin
Outlook Synchronisieren
Riester-rente
скачать книгу

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com