Virus Database


Deliver.Digi.3547

Description Deliver.Digi.3547

This is a polymorphic stealth virus. It hooks INT 1, 3, 1Ch, 21h and writes itself to the end of COM- and EXE-files that are executed. While creating, opening and executing COM- and EXE-files it stores their names, and hits them on the files closing. On opening of infected files the virus disinfects them. On FindFirst/Next DOS calls it "decreases" the infected file length. The virus deletes CHKLIST.* files, while execution of CHKDSK utility it disables its FindFirst/Next handler, while execution of MKS anti-virus scanner is stops the infection. It disables the debugging of the virus code by hooking INT 1, 3.
On May, from 28th till 31th the virus overwrites the hard drive sectors with the strings:
DIGI POWER
Then it manifests itself with the video and sound effects, and displays the message:
DIGI POWER
THIS IS A NEW all
DELIVER II SÆëâlÆH (R) WRITE BY DiGiT! ... SOUTH POLAND 1995

Check other viruses! Be aware! Use Antiviral Software

November17.522

Description November17.522

These are dangerous memory resident parasitic viruses. They hook INT 21h and write themselves to the end of COM and EXE files that are executed, "November17.584" infects COM files only. They use the address of INT 83h as the virus ID-word. Depending on the current time these viruses erase CMOS or disk sectors. "November17.584" hooks INT 8, 9 and manifests itself with a sound effect.
Some versions of these viruses contain the string "SCAN.CLEAN.COM.EXE" and do not infect the SCAN.EXE and CLEAN.EXE files.

Novosibirsk.1000

Description Novosibirsk.1000

It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed or accessed. When any infected program is executed the virus also searches for first EXE file in current directory and infects it.
The virus uses not accurate way to install itself into the system memory. As a result it can halt the system. The virus cancels access to hidden disk files by DOS Find calls, as a result the hidden files on computer stays "invisible" for DOS file managers and "DIR /AH" command. The virus contains the text strings:
WRA
NOEMS
Novosibirsk

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z




    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com