Virus Database


Xute.1182

Description Xute.1182

This is a very dangerous memory resident encrypted parasitic virus. It hooks INT 8 and 21h, and writes itself to the end of EXE files that are accessed. On Thursdays which coincide with the 8th of the month, it erases hard drive sectors, CMOS, and displays the following messages:
HACKWARE
NO ES POT SER TAN SIMPLE COM L`OSOFT
AGRAIMENTS A TOTS ELS COL.LABORADORS

The virus also contains the text string:
Prog: Xute!!!

Check other viruses! Be aware! Use Antiviral Software

Ghh.482

Description Ghh.482

It's a dangerous memory resident parasitic virus. It hooks INT 1Ch, 21h and writes itself to the beginning of COM-files that are executed. On each timer tick (INT 1Ch) it scans the screen for the "THE GHH" string, and erases the disk sectors if that string is found.

Ghost

Description Ghost

It is a dangerous memory resident boot virus. It infects the MBR of the hard drive and boot sector on floppy disks. While infecting the virus saves the original MBR sector on the hard drive at the address 0/0/8 (track/head/sector) and the original boot sector of floppy disks to the last sector of root directory.
On loading from infected disk the virus copies itself into Interrupt Vectors Table and hooks INT 13h. It then infects floppy disks that are accessed. The hard drive MBR gets infection while loading from infected floppy disk.
While loading from infected floppy disk, if the MBR is already infected, the virus disinfects it: restores the original MBR image and fills sector 0/0/8 with zero byte. While disinfecting the virus leaves its "signature" in the last entry in Disk Partition Table: "GHOST".
The virus uses quite risky anti-debugging trick and as a result halts Pentium computers.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



сходи на горище
Lebensversicherung
Glass
ALLRADIO AKTIEBOLAG, UPPSALA

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com