Virus Database


XM

Description XM

XM.823
These are not dangerous memory resident encrypted parasitic viruses. They hook INT 21h and write themselves to the end of COM and EXE except COMMAND.COM files that are executed, opened, renamed or when file attributes are read or modified. While installing memory resident the viruses with probability 1/8 (depending on the system timer) display the message:
[XyeBo_MHe], (c)Midnigh+Pr0wler

This viruses were posted to Russian local FIDO conferences in June 1998 and then found In-The-Wild.
XM.2379
It is a dangerous memory resident polymorphic parasitic virus, the polymorphic decryption code uses anti-debugging tricks. The virus hooks INT 21h and writes itself to the end of COM and EXE files that are executed. It does not infect the files: æOMMAND.COM, DOS4GW.EXE, IBMIO.COM. While installing memory resident the virus also scans the C:AUTOEXEC.BAT file and tries to infect files listed there.
On opening the SF-MAIL.CFG file the virus appends to it the strings:
[Miscellaneous]
DoorWay_Password 'GLORY'

On opening the T-MAIL.CTL file the virus adds the string:
T-Password GLORY

Under debugger the virus overwrites traced file with the text:
[X&^%$_MHe], (c)Midnigh+Pr0wler -=Version 2.1=-
Bugs fixed! Almost harmlessall

Check other viruses! Be aware! Use Antiviral Software

BG.2135

Description BG.2135

This is a benign memory resident encrypted parasitic virus. It hooks INT 8 and 21h. Upon DOS calls, CreateDir, ChangeDir, Close, Execute, Get/Set FileAttributes, and Rename, the virus searches for COM and EXE files and writes itself to the end of the file.
When the F12 key is pressed, if the NumLock, CapsLock and ScrollLock keys are on, the virus displays a message in Russian. The virus contains the text strings:
=> üâ Virus Ver. 2.0 <=
*.COM *.EXE

BG.3178

Description BG.3178

This is a very dangerous memory resident parasitic polymorphic virus. It hooks INT 21h, and writes itself to the end of EXE files that are accessed. This virus writes file texts in Russian to TXT, PAS, CPP, DIZ and NFO files. The virus also contains the text:
=> üâ Virus Ver. 3.0 <=

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Meet & Greet Manchester Airport
Perma Clean
Ringe
Ac298190237
Internetagentur Hamburg

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com