Virus Database


DIW.386

Description DIW.386

These are non-memory resident parasitic viruses. They search for .COM-files, then write themselves to the end of the file. The viruses contain the following text string:
*.com

and:
"DIW.386": *.dbf
"DIW.389": *.exe
"DIW.512": *.dbf aidstest.* adinf.* *.txt *.doc
"DIW.565": *.dbf clip????.* ?link.* *.obj *.arf
"DIW.597": ELEFANT

"DIW.212,229,288" are harmless viruses, and they do not manifest themselves in any way.
"DIW.377", dating from 1999, halts the system. It also resets the active partition flag in the MBR of the hard drive.
"DIW.386,389" checks the system date and time, and if the day number is equal to month number, e.g, 9 September = 9/9, and if the hour counter is equal to the minutes counter, these viruses search for files, and delete them:
"DIW.386": *.BDF-files
"DIW.389": *.EXE-files

"DIW.393" displays:
DIW 1.0
*** MORNING STAR ***
Press any key to continue all

This virus also contains the text strings in Russian.
"DIW.428" changes the video palette registers. "DIW.480" "shakes" the screen. "DIW.488" changes the settings of the system timer.
"DIW.512,565" searches for files and deletes them from the following filenames:
"DIW.512": *.DBF AIDSTEST.* ADINF.* *.TXT *.DOC
"DIW.565": *.DBF CLIP????.* ?LINK.* *.OBJ *.ARF

"DIW.555" reboots the system or displays the messages in Russian. This virus also contains the following text string:
DIW 2.0

"DIW.597" "eats" the screen. "DIW.600" deletes files:
CHK*.* *.___
[NOTE: "___" not displayable ASCII chars]

On the 13th of any month, this virus deletes *.EXE-files, on November 28th, it corrupts MBR and displays the following message:
User PC - I N F E C T E D !
Call Lozinsky !
(c) VIRUSOFT Inc.

Check other viruses! Be aware! Use Antiviral Software

Noki.448

Description Noki.448

This is a very dangerous, memory resident parasitic virus. While executing, the virus copies its code into the video memory at the address BD00:0000, and saves its code on the hard drive to sector 17 (17/0/0 - sector/track/head). Then the virus copies its INT 21h handler code (39 bytes) into Interrupt Vectors Table, hooks INT 21h, and returns control to the host file.
The virus intercepts the file execution (AX=4B00h), reads its code from hard drive sector 17 to the video memory, and jumps to there. The infection routine gains control, and infects EXE files that have the 448-bytes "cave" of zero bytes. The virus overwrites that cave, and returns from an infection routine. Thus, the file length does not grow during infection.
On the 17th of odd months (January, March,all), the virus corrupts the MBR of the hard drive. The virus contains the following text string:
NOKI

Nomad.888.a

Description Nomad.888.a

Nomad.888
It is not a dangerous nonmemory resident parasitic virus. It searches for EXE files, then writes itself to the end of the file. The virus searches for files in the current directory and in first four directories that are listed in PATH. Depending on the system timer the virus displays the message:
*******************************************************
* yO!!! I could have made some mischief to you but I *
* lEfT it out. I'm the #Nomad Virus# - Mikee's World *
*******************************************************

Nomad.1022
It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM and EXE files that are executed. The virus deletes the anti-virus data file ANTI-VIR.DAT. Depending on the system time the virus displays the message:
+-----ùú[Nomad By SeptiC]úù------+
: Travling through the time, :
ù Moving slowly in your files, ù
ú Knowledge is the weapon, ú
: That makes my travel fast. :
+-----ùú [-Nomad v 1.0-] úù------+

Home

Viruses from A to Z
0-9 A B Ñ D E F G H I J
K L M N O P Q R S T
U V W X Y Z



Chopin Calling Card
Download Games For Pc
The Proxy School
Bat Mitzvah In Chicago Il
Radon

    Copyright © 2005 Virus-Database.com
© 2005 Virus-Database.com