DM.330
Description DM.330
This is a harmless memory-resident virus. It hits by standard way COM files whenever it is loaded into the memory, opened, renamed or their attributes are changed. The virus writes its TSR copies into the interrupt vector table at the address 0000:0200. It hooks INT 21. It contains the following texts: (C)DM 1991 1.05 DM
Check other viruses! Be aware! Use Antiviral Software
GD.539
Description GD.539
It is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. Depending on the system time the virus overwrites boot sector and the FAT of the C: drive and display the message: Grave-digger!!!
GDIKill.1288
Description GDIKill.1288
This text was written by Alexey Podrezov, F-Secure Corp. Being run it first goes to C:WINDOWS folder. Then it checks current date and if the month is not March it passes control to original WIN.COM code. If the date is 14th of March, the virus just deletes GDI.EXE, outputs a message and passes control to original WIN.COM code. If the virus starts from a dropper (it checks 1 byte flag for that), it looks for WIN.COM file and infects it. The virus author planned that his virus would infect other COM files in case WIN.COM is already infected, but there's a bug in virus code and this doesn't happen. Also there's a routine in virus code that goes to FONTS folder and deletes all files there. But this routine is never activated.
|