Win95.Uwaga
Description Win95.Uwaga
This is a relatively harmless, non-memory resident parasitic Win95 virus. It searches for PE EXE files, then writes itself to the end of the file, increases the size of the last section, writes its code there and modifies the entry-point address. To gain access to the Windows file access function, the virus scans Win95 Kernel32 internal formats. To detect previously infected files, the virus compares section names with its own section name "BEDM." The virus also does not infect files compressed with the Petite PE files compression utility. On February 25th, the virus displays the following MessageBox: Rafa+ ! Wszystkiego najlepszego z okazji urodzin !
On the 13th of any month, it displays the following MessageBox and exits Windows: Uwaga !Aby uruchomiæ ten program musisz zresetowaæ komputer !
The virus also contains a text that contains names of functions and libraries used by the virus: KERNEL32.DLL USER32.DLL GetModuleHandleA GetProcAddress FindFirstFileA FindNextFileA SetCurrentDirectoryA GetCurrentDirectoryA CreateFileA ReadFile WriteFile SetFilePointer CloseHandle GetSystemTime LoadLibraryA MessageBoxA ExitWindowsEx
Check other viruses! Be aware! Use Antiviral Software
Murcia.4651
Description Murcia.4651
It is not a dangerous memory resident partly encrypted parasitic virus. Being executed it searches for .COM files (except COMMAND.COM) in the subdirectory tree, then writes itself to the beginning of the file. The virus searches for the FLOWEROF.MAY file, and terminates the infection routine if that file is found. Next the virus hooks INT 8, 21h, stays memory resident, and when any file is executed, the virus searches for .COM files and infects them in the same way as described above. Two months after infecting a computer the virus manifests itself in several ways. First, it creates the MURCIA!!.nnn file, where 'nnn' is the internal virus counter, then writes the text string to that file: MURCIA (SPAIN): THE BEST PLACE IN THE WORLD! WHERE THE PEOPLE MAKES VIRUSES FOR YOUR COMPUTER! NOW, IN SPANISH: ¿SABES LO FACIL QUE RESULTARIA BORRARTE TODOS LOS FICHEROS DEL DISCO? O MEJOR AUN: FORMATEARLO. QUE PASES UN FELIZ DIA.
Then the virus manifests itself with a video and sound effects. The virus also contains the text strings: BOYA_PARA_MOV FLOWEROF.MAY COMMAND.COM MURCIA!!.003
Murderer.3670
Description Murderer.3670
It is a dangerous memory resident parasitic virus. It hooks INT 5, 8, 13h, 17h, 21h. On DOS calls CloseFile it searches and infects .COM and .EXE files. It writes itself to the beginning of .COM files, .EXE files are infected by companion manner. That virus erases the disk sectors. On July, 3rd it displays the messages and plays a tune, the virus also prints the text: To the human: The emperor of darkness "Satan" has came back from hell, and he will destroy the world, all human will be take to the horrendous darkness. But one man who can fight with Satan, "Son of brightness" has born. He will lead us to fight with Satan, and kick him back to the hell. So, hurry up, go to Taiwan to find our rescuer ==> Chinq-shyang Lay. << All augur >>
It also contains the text strings: <<< MURDERER Version 1.44 >>> IBMBIO.COM IBMDOS.COM COMMAND.COM SHEAU-YN.LIN Bad command or file name
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Buy Ukraine Nude Photos Rca Ieftin Outlook Synchronisieren Riester-rente скачать книгу
|