Virus Database


Debilas.2000

Description Debilas.2000

It is a very dangerous memory resident parasitic virus. It hooks INT 8, 21h and writes itself to the end of .COM- and .EXE-files that are executed or opened. The virus checks the file name, and does not infect the file if the file name contains the symbols:
AI CL WE AD AN SC V. LD PR MM

On September, 16th the virus erases the disk sectors, decrypts and displays the messages:
Copy right Antanas Vidziunas ,VDU, 1996.
Buvai DEBILAS , esi DEBILAS ir busi DEBILAS !!!
-=DMS=-
Fuck you b.tAMULYNAS and to your crack of Print_Screen

The virus also contains encrypted text strings:
AICLWEADANSCV.LDPRMM
I `LL BE IN KTU SOMEDAY

Check other viruses! Be aware! Use Antiviral Software

LoveChild.2710

Description LoveChild.2710

This is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files.
It is a stealth virus. It hooks INT 13h, 21h and writes itself to the end of COM files. It works on DOS 3.30 only because it inserts itself into the DOS data area. In cause of the another DOS the virus displays the message in Russian and erases the MBR. From the midnight till 4 o'clock it prints the screen. Sometimes it displays the long message in Russian and then erases the disk sectors.

LoveChild.488

Description LoveChild.488

This is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files.
It copies itself into Interrupt Vectors Table at the address 0000:01E0, and then infects COM files that are loaded into memory, opened or created. While infecting the virus writes four bytes of Jmp-Virus commands to the file (STI; JMP Loc_Virus).
If DOS 3.30 is installed on the computer, the virus takes masking actions - the virus "knows" the INT 21h handler address and the address at which the original value of the INT 13h is stored. Using this, the virus modifies the memory occupied by the operating system in such a way, that it handles the 21h interrupt call immediately before DOS (the JMP FAR Loc_Virus - jump to the virus, is written instead of the first 5 bytes of the interrupt 21h handler). Int 13h is treated by the virus by simple way - the original value of interrupt is restored.
The virus has destructive functions: depending on the timer it might delete files or create instead of a file a subdirectory with the same name. The virus periodically modifies EXE files in such a way, that their execution causes erasing the hard disk sectors (part of the information located in the sectors corresponding to the write/read heads 0-3).
This virus contains the texts:
v2 (c) Flu Systems (R)
LoveChild in reward for software sealing

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Trekking.net: Nepal, Chile
Colon Cleanse
Compaq/hp Notebook Hard Drives
Sport Games
New Dvd Releases

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com