DrJohn.2000
Description DrJohn.2000
It is not a dangerous memory resident parasitic virus. It writes itself to the end of COM and EXE files. When an infected file is executed, the virus infects the C:COMMAND.COM file, then hooks INT 13h, 21h and infects the files that are opened. Depending on the system date (one month after infecting) the virus displays the message in Russian. The virus also contains the text strings: c:command.com *Doctor John*!
Check other viruses! Be aware! Use Antiviral Software
RiftVilly family
Description RiftVilly family
These are harmless memory resident parasitic viruses. They hook INT 21h, and write themselves to the end of COM files. "RiftVilly.469" intercepts file access to DOS functions and infects COM files that are executed, opened or renamed; "RiftVilly.490" does the same with EXE files. "RiftVilly.480" intercepts a ChangeDir DOS function, and upon such calls, searches for .COM files in the current directory and infects them. The viruses contain the following text strings: "RiftVilly.469": Rift Villy v.3.4 "RiftVilly.480": Rift Villy v.3.1 "RiftVilly.490": Rift Villy v.4.0
Rikki family
Description Rikki family
These are not dangerous nonmemory resident parasitic viruses. They search for .COM files, then writes itself to the end of the file. While infecting a file they temporary rename it with COx (x=FFh) extension. To rename file the viruses do not call any DOS function, but make it by absolute disk read/write calls (INT 25h/26h) - the viruses read directory entry, search for file name, patch it and then write directory sector back to disk. The viruses display the messages: "Rikki.839": Demo virus #1 by Rikki Cate 21/9/90 File infected: Press key to continue
"Rikki.1787": Demo virus #3 by Rikki Cate 21/9/90 File infected: Press key to continue
"Rikki.1970" Demo virus #2 by Rikki Cate 21/9/90 File infected: Press key to continue PC-cillin has been replaced by a demonstration virus. To activate the virus, reboot the computer. PC-cillin has been replaced by a demonstration virus. This message could easily duplicate the PC-cillin start-up screen. The virus is now resident in memory in place of PC-cillin. It will emulate the PC-cillin display and command keys. It will also infect any .COM programs which are accessed by interrupt 21 hex. Press any key to continue.
|
Home
Viruses from A to Z 0-9
A
B
Ñ
D
E
F
G
H
I
J
K
L
M
N
O
P
Q
R
S
T
U
V
W
X
Y
Z
StÄd Experten I Halmstad Timeport JÄmjÖ TrÄindustri Ab Globen Mur Och Puts Handelsbolag Salong Ib KlipphÖrnan
|