Virus Database


WWPE.Rsa.4568

Description WWPE.Rsa.4568

It is a very dangerous memory resident parasitic polymorphic virus based on WWPE mutation engine. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed, opened, or accessed by Get/Set Attributes DOS call. The virus also affects ARJ and ZIP archives - when these archives are accessed, the virus adds to their contents the infected C00LBBS.COM file. This file also contains virus video effect - when it is executed, it drops the virus and displays flame on the screen.
Depending on the system timer the virus disables writing to files - that may corrupt data on disk. The virus has bugs and may halt the system or/and corrupt files while infecting them. The virus contains the text strings:
$$temp$$
Wild W0rker /RSA
WWPE v0.1

Check other viruses! Be aware! Use Antiviral Software

QPHS.2931

Description QPHS.2931

It is not a dangerous memory resident multipartite virus. While executing an infected file the virus infects the MBR of the hard drive, hooks INT 9, 13h, 21h and stays memory resident. While infecting the hard drive the virus encrypts the original Partition Table. On reading the MBR the virus calls the stealth routine and returns the Partition Table in its original form.
While loading from infected MBR the virus hooks INT 8, 9, 12h, 13h, waits for DOS loading, and then hooks INT 21h. The virus uses INT 12h to hide itself in the system memory during the DOS installation procedure.
By hooking INT 21h the virus intercepts COM and EXE files opening, execution and searching. The virus writes itself to the end of the files on A: and B: drives only, and disinfects the infected files on other disks.
The virus pays special attention to the execution of LOGIN.EXE file, and saves the command line and entered from keyboard symbols during execution of LOGIN.EXE. By using that trick the virus allows to intercept login commands (user names and passwords).
The virus intercepts the symbols entered from keyboard. On entering the "QPHS" string the virus display the intercepted login commands. On entering the "PERFECT" string the virus disinfects itself in the MBR of the hard drive.

Quadratic Family

Description Quadratic Family

These are harmless memory resident parasitic virus. They hook INT 21h and write themselves to the end of COM- and EXE-files that are executed. They cure the infected files on file opening. They contain the internal text strings:
SD93
Quadratic Equation

"Quadratic.981,986" hook INT 09h also (keyboard) and sometimes display the message "Quadratic Equation" on DEL key pressing.
"Quadratic.1283" is a polymorphic virus. It contains the internal string "Quadratic Equation II".

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Toner
Plexiglass
Promat Videos
Dime Squad Studios
Svensson, Mats Stefan

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com