Christ.483
Description Christ.483
This infector is harmless and memory-resident. It writes itself into COM-, EXE- and OVL-files by standard manner. The virus hooks INT 21h. On April, 1st the virus displays the text (in Russian), saying that the "Christ raises from the dead!".
Check other viruses! Be aware! Use Antiviral Software
Starcon.1057
Description Starcon.1057
It is a dangerous memory resident partly encrypted parasitic virus. It hooks INT 21h and writes itself to the end of .COM files that are executed, opened or accessed by FindFirst/Next DOS call. The virus deletes STARCON.* files and contains the text string: starcon
Starship
Description Starship
This is a memory resident and not dangerous stealth polymorphic virus. It infects only newly created COM- and EXE-files on the A: and B: drives. The virus also infects MBR of the hard disk if an infected file is started. As a result of this policy the virus stays resident in memory and can be moved to other computers with the minimum of the infected objects. So it is more difficult to find the virus. There is one more reason to use such a policy: when only newly created files are infected there is no need to control the DOS fatal errors (INT 24h). The virus infects files in a standard way using the polymorphic mechanism. To infect a disk the virus puts itself into the last sectors of it, replaces the active boot sector address in the Partition Table with its own starting address. During an access to MBR or to the last sectors the virus uses stealth mechanism. The virus infects the memory during rebooting from an infected disk. It places some part of its TSR copy into the interrupt vectors table (0000:02C0) and into BIOS Data Area (0000:04B0); the main part of the code is placed into the video RAM (BB00:0050). When the operating system is loaded the virus looks for other programs. If some program has been swapped from the memory (Exit - INT 20h, INT 21h and ah=0 or 4Ch) the virus moves from the video RAM to the place of the program. If a program remains resident (Keep - INT 27h, INT 21 and ah= 31h) the virus "attaches" its code to the program body. The virus recovers its main part in the video RAM if this part has been corrupted, and does this from the disk. Depending on the internal counters the virus "beeps" using Morse code and shows "stars" on the screen. It contains the string ">STARSHIP_1<". The virus hooks INT 13h, 20h, 21h, 27h.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
MARKSÖM AB ALLAN REHNSTRÖM AB ASSIST SERVICEKEDJAN AB Ecco Finishing Ab Halterlose Strümpfe Shop
|