Dennis.1000
Description Dennis.1000
This is a memory resident parasitic virus. It infects COM and EXE files that are executed or opened. It also hooks INT 13h to avoid DOS error message while infecting a file on write-protected disk. It contains the text string: execomûD.Davydov
Check other viruses! Be aware! Use Antiviral Software
Dreamer.4808
Description Dreamer.4808
These are not dangerous memory resident parasitic viruses. They hook INT 1Ch, 21h and write themselves to the end of COM files that are executed. Sometimes these viruses try to speak several words by the internal speaker. The viruses contain the text strings: "Dreamer.4808": Hitler Virus by Dreamer/DY "Dreamer.8869": [Dar Mandra] by Simpson #1
Drepo.2461
Description Drepo.2461
These are not dangerous memory resident encrypted parasitic viruses. While executing an infected EXE file the virus reads the root directory of C: drive by using INT 25h direct read call, searches there for the "COMMAND COM" string in the read buffer, replaces that string with "COMMAND LOM", clears the file attribute field, and saves the result to the disk by using direct write INT 26h call. Then the virus opens the C:COMMAND.LOM file (ex-COMMAND.COM), encrypts and writes itself to the end of the file to the COMMAND.COM stack area (the file length does not grow, see "Lehigh"), and then overwrites the file entry point (the code that is pointed by JMP instruction at the file beginning) with 2Eh bytes of a decryption routine. Then the virus restores the original contents of the root directory (also by using INT 26h call) and returns the control to the host EXE file. I see that such complex way to infect the file is to avoid memory resident anti-virus monitors. While executing the infected COMMAND.COM the virus hooks INT 21h, stays memory resident and writes itself to the end of EXE files that are opened or closed. When the archivator ARJ.EXE or RAR.EXE is executed, the virus reserves an extra block of the memory to infect the files that are compressed or extracted from an archive. The virus also hooks INT 9 (keyboard) and two month after infecting a system, depending on the keys that are pressed, it beeps by the PC speaker. The virus contains the text strings: ARJ.EXE RAR.EXE C:COMMAND COM Pod na jedno DREPO! Shareware version. Do not forget to register!
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
|