Virus Database


Clisti.1025

Description Clisti.1025

It is a very dangerous memory resident encrypted multipartite virus. It hooks INT 21h, 40h and writes itself to the end of COM files that are executed, and to boot sectors of floppy disks that are accessed. While loading from infected floppy, or while executing infected file the virus writes itself to the boot sector of C: disk. Depending on its counter the virus erases the disk sectors.

Check other viruses! Be aware! Use Antiviral Software

Lokjaw family

Description Lokjaw family

These are dangerous memory resident viruses. They hook INT 21h and infect .COM files that are executed. They manifest themselves with a video effect - draw a picture which is the same as "Malmsey" virus does.
Lokjaw.493,499,501,507,518,520,522,894,898
These are companion viruses. They create companion .COM files while executing .EXE files. They contain the text strings:
"Lokjaw.493": loulou
"Lokjaw.493.b": Arclight
"Lokjaw.499": Good Night
"Lokjaw.501": SLEEPWALKER
"Lokjaw.507": Starry Night Bornio Baby
"Lokjaw.518,520,522": Black Knight EXE COM Tempest - Of Luxenburg
"Lokjaw.808,894": Lokjaw-Zwei
"Lokjaw.898": Lokjaw-Drei

If one of several anti-viruses is started (SCAN, CLEAN, NAV, F-PROT) "Lokjaw.493,499,507,520" erase the disk sectors, "Lokjaw.808,898" display the picture (see above) and halt the system, "Lokjaw.894" deletes the file is executed, and displays the same picture.
Lokjaw.1041,1050,1052,1053
These are parasitic viruses. They write themselves to the end of .COM files that are executed. While executing some antiviral programs (SCAN, CLEAN, NAV, F-PROT) these viruses draw the picture (see above) and delete that program. They contain the ID-string "CD" and:
"Lokjaw.1052":
KenSON IV Infection Module VIRUS
Proto-T Variant 94/Lobo/435
Thanks To Brian! - BF?

Lokjaw.Firefly
These are memory resident parasitic encrypted viruses. They hook INT 1Ch, 21h and write themselves to the end of .COM files that are accessed. Depending on their internal counters they change keyboard flags. When some anti-virus programs are executed, these viruses delete them. The viruses contain the text strings:
"Lokjaw.Firefly.1087":
[Firefly] By Nikademus
Greetings to Urnst Kouch and the CRYPT staff.
American Jesus
Dont Pray On Me
Recipe for HAte
Atomic Garden
Its Dead Jim

"Lokjaw.Firefly.1106":
[Firefly] By Nikademus
Greetings to Urnst Kouch and the CRYPT staff.
Psalm 69
Every day is Halloween
Happiness in Slavery
The land of Rape and Honey
Its Dead Jim

Lokjaw.Kenson
These are companion viruses. They create companion .COM files on execution of .EXE files. They contain the text strings:
"Lokjaw.Kenson.573":
[ Its the KenSON III virus ]
EXE COM For My Very Best Friend allBy Lobo 435 of Covina CA...

"Lokjaw.Kenson.887":
KenSON V - Lobo/435 BF! :)
EXE COM For My Best Friend, the Fifth in a Series!!!

On execution of some anti-virus programs "Lokjaw.Kenson.573" erases the disk sectors, "Lokjaw.Kenson.887" manifests itself with a video effect.
Lokjaw.Pfeiffer,Scramble
These are harmless memory resident encrypted parasitic viruses. They hook INT 21h and write themselves to the end of .COM files that are executed or accessed by FindFirst/Next FCB functions (DIR command). They contain the text strings:
"Lokjaw.Pfeiffer": Pfeiffer
"Lokjaw.Scramble.1253":
BEER and TEQUILA forever !
[Scramble] By Nikademus
Read CRYPT Today!.
"Lokjaw.Scramble.1254":
Windows 95 forever !
[ResEvil] By Crypto Copyright(c)1997 -Germany-

Lonely.1000

Description Lonely.1000

It is not a dangerous memory resident encrypted parasitic virus. It hooks INT 9, 1Ch, 21h and writes itself to the end of EXE files that are executed or closed. On opening an infected file the virus disinfects it. The virus also disables its infection routine after entering some keyword. The virus manifests itself only by changing the keyboard flags ("presses" the left shift key). The virus contains the text string in Russian.

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com