Cybercide Family
Description Cybercide Family
These are dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of .COM-files. "Cybercide.1288,1307,1321" store the names of the files on DOS calls FindFirst/FindNext and OpenHandle. On call to DOS function GetDiskSpace they infect the files that are stored. They hit the files on DOS call CloseHandle also. "Cybercide.2229,2256" hit the files on FindFirst/FindNext DOS calls only. On opening the infected file the viruses disinfect it. "Cybercide.2229,2256" hook INT 09h, 1Ch also and call trigger routine from these handlers. On typing "anoi" on keyboard these viruses add "iS AROUND!", on pressing Alt-Del they display chars 'A', 'N', 'O' and 'I' in four corners of the screen. Depending on system timer they either displays color cross in background (looks as Swedish national flag), or play the tune (the Imperial March from "The Empire Strikes Back") and display the message and then halt computer: or erase random selected disk sector by the string: >>> A.N.O.I <<<
"Cybercide.1288,1307,1309,1321" erases the disk sectors. These viruses contain the internal text strings also (some of them are written backward in "Cybercide.2229,2256"): "Cybercide.1288": huh huh m huh m huh hu hu hu huh huh huh m huh mhu huh hu huh huh Im going to kick your ass again (c)1995 Etheopia Virus: Butt-HeadAuthor: Etheopia/FLooD Uhhhh, Hey baby..
"Cybercide.1307,1309": Simple Simon met a pieman going to the fair said Simple Simon to the pieman let me take your ware (c)1993 Cruel Entit %%% MY LITTLE PONY %%% COPYRIGHT(C) 1993 A.N.O.I. %%% >>> A.N.O.I <<<
"Cybercide.1321": simple simon met a pieman going to the fair said simple simon to the pieman let me take your ware - my little pony - copyright(c) 1993 Cruel Entity and A.N.O.I. - .. sweden rise again ..
"Cybercide.2229,2256": nam nesut agnåm dem änk mo änk ,marfkcig xeR sluloraC ruh nes egnäl röf ,nä in snniM YTITNE na ot LEURC eb reven ynollef ELIV a si GINKLAWYAJ all I SHALL FEAR NO EVIL ... **CYBERCIDE** -- FLOATING THROUGH THE VOID -=CYBERCIDE=- 01-30-1993 * COPYRIGHT (C) 1992-93 A.N.O.I DEVELOPMENT
Check other viruses! Be aware! Use Antiviral Software
Frida.538
Description Frida.538
It is a not dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the beginning of .COM-files that are executed or opened. On August, 1st it displays the message: FRIDA
It contains the internal text strings: LoRD Zer0
Friday13.540
Description Friday13.540
This is a non memory resident dangerous parasitic viruses. It searches for all COM files (except COMMAND.COM) of the current directory, and writes itself to their ends. On Friday, 13th it deletes the files that are started. It contains the texts: *.COM COMMAND.COM INFECTED The virus displays the messages: WARNING!!!! THIS PROGRAM IS INFECTED WITH VIRUS-B! IT WILL INFECT EVERY .COM FILE IN THE CURRENT SUBDIRECTORY!.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|