DirII.Dragon.a
Description DirII.Dragon.a
This is a memory resident dangerous stealth virus. It infects COM and EXE files during read/write operations with the sectors which belongs to the directories, containing information about these files. The virus places its own bodies into the last cluster of the infected logical disk. It marks this cluster as the last in the file cluster chain. When the virus infects the file it replaces only the number of the first cluster of the file. The new number will point to the body of the virus. So the virus don't change the contents and the size of the infected file and besides there will be only one copy of the virus on the disk. During initialization the virus penetrates into the DOS kernel, modifies the address of the system disks driver and hooks all DOS calls to this driver. This virus uses powerful stealth mechanism on the system driver level. That is why the virus is "invisible" during a read of infected files either with INT 21h or INT 25h. This virus uses direct access to DOS resources and overcomes practically all anti-virus "shields". This virus spreads with great speed. If you try to load a file which can't be found on the disks, DOS will look for it in all PATH directories and the virus will infect all the files in these directories. During the first start this virus will infect all files in the current directory of C: drive. It opens the file "c:dragon.com" to infect root dir of C: disk. Depending on some cases it overwrites the files with the string: DRAGON ver 1.0 Copyright (c) MicroVirus Corp. 1993 The Lords of the Computers ! DRAGON - the Lord of Disks ! anti
Check other viruses! Be aware! Use Antiviral Software
AntiTrace.2122
Description AntiTrace.2122 It's a not dangerous memory resident parasitic virus. It hooks INT 21h and writes itself at the end of COM-files on their closing. On infected file opening it disinfects it. The virus uses anti-debugging tricks, on tracing of INT 21h it displays the message: +--------- Anti_Trace ----------+ ƒ ƒ ƒ Loading AntiVirus didn't find ƒ ƒ me yet. I'm so sorry! ƒ ƒ ƒ ƒ [ Continue ] ƒ +-------------------------------+ It contains the internal strings also: Anti_Trace Good Luck in Creating Antivirus. (C) 1993, AT Corp.
AntiWin
Description AntiWin
It is not a dangerous boot virus. It hooks INT 9 (keyboard), INT 13h and writes itself to the boot sector of floppy disks and to the MBR of the hard drive. It infects boot sectors that are accessed and the hard drive while loading from infected floppy drive. On pressing "Windows" key (on Microsoft keyboard) the virus halts the computer. The virus contains the string: AntiWin95
|