Disque
Description Disque
It is not a dangerous memory resident boot stealth-virus. It hooks INT 13h and writes itself to the MBR of the hard drive and boot sectors of floppy disks. The virus sets new date: 2097 year. It contains the text: Disque non-syst
Check other viruses! Be aware! Use Antiviral Software
Shrapnel.6067
Description Shrapnel.6067
It is a dangerous memory resident multipartite stealth virus. It writes itself to the end of COM, EXE and NewEXE files (Windows) as well as to the MBR of the hard drive and boot sector of floppy disks. When an infected file is executed, the virus checks the presence of MS Windows. If Windows is installed, the virus searches for EXE files in the current directory and infects them. Then the virus infects the MBR of the hard drive. If Windows is installed, the virus uses direct calls to hard drive ports to write data to the disk. The virus then returns control to the host program. While loading from an infected disk the virus hooks INT 13h, 1Ch, waits for DOS loading process and hooks INT 21h, 2Fh. The virus then writes itself to the end of files that are executed. When PKZIP or ARJ archivers are run, the virus disables its stealth routines. The virus does not infect the files (anti-viruses, utilities, and more) TBAV, COMMAND, WIN, SCAN, AVP, F-PROT, NAV and so on according to the string (two letters per name): TBCOWISCVIAVVAF-NAVSIVFIFVIMQBMSDODESW
The virus deletes the file: C:WINDOWSSYSTEMIOSUBSYSHSFLOP.PDR
Depending on its counters the virus creates the subdirectory SHRAPNEL on the disk. The virus also contains the texts: SHRAPNEL v1.0 by PH Made in the USA *.EXE
ShuHard.386
Description ShuHard.386
It is not a dangerous(?) memory resident parasitic virus. It copies itself to Interrupt Vectors Table, hooks INT 21h and writes itself to the end of COM files (except COMMAND.COM) that are closed. While infecting a file the virus uses not documented DOS calls and System File Tables. When files are executed the virus scans the command line for "doom" text. If it is found, the virus modifies the i386 register CR0 - it sets on the reserved bit (CR0 OR 40000000h). The virus also reverses that bit when any program is executed. The virus contains the text strings: doom VM DOOM MD! R.ShuHard 1997
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
Marijuana Detoxification Time Rekrytering Hoodia Diet Athletikum Group
|