Prevent Online Threats

Archive for September, 2007

MSTU.51

Friday, September 28th, 2007

Details
MSTU.513

These are very dangerous nonmemory resident parasitic viruses. They search for .COM and .EXE files in the current directory and write themselves to the end of the file. While infecting the viruses might corrupt the files. The viruses contain the texts:
This program was written in MSTU,1990
*.exe *.com

MSN-Worm.Jitu

Friday, September 28th, 2007

Details
MSN-Worm.Jitux
Jitux is an Internet worm that spreads via the MSN Messenger system. It is written in Visual Basic and its’ size is about 24KB.
The worm sends messages with the URL of the downloadable version of the worm.
Once the worm is launched, it scans the victim MSN Messenger contact list and sends all contacts the following message:
http://www.home.no/[censored]/jituxramon.exe
Jitux repeats this process over set intervals (about 1 minute).

Msk.27

Friday, September 28th, 2007

Details
Msk.272

It is a very dangerous nonmemory resident virus. It searches for all .EXE files of a current directory and overwrites them. It erases the sectors of C: disk, displays the message:
The Midnight Serial Killer is roaming in your computerallBeware! [JD]

Mshark Famil

Thursday, September 27th, 2007

Details
Mshark Family

These are the harmless viruses. The write themselves to the end of the files, contain the texts:
“Mshark.373,378″: (C) Mshark-S v.1.0
“Mshark.889″: (C) Mshark v2.10 1992

Mshark.373,378
These are nonmemory resident viruses. They search and infect .COM files of the current directory.
Mshark.889
It is a memory resident virus. It hooks INT 21h and infects .COM and .EXE files that are executed.

MS.74

Thursday, September 27th, 2007

Details
MS.748

This is a very dangerous non-memory resident parasitic virus. It searches for .COM files, and writes itself to the end of the files. On Saturday at 5 a.m., it overwrites .EXE files with a little program that erases random sectors of the hard drive, and displays randomly selected letters. The virus contains the text string:
MS*.COM *.EXE

Mrvirus.50

Thursday, September 27th, 2007

Details
Mrvirus.508

It is a harmless nonmemory resident parasitic virus. It searches for .COM files and writes itself to the end of the file. It contains the text strings:
Mr.Virus Ver. 1.10
*.COM

MrTwister Famil

Thursday, September 27th, 2007

Details
MrTwister Family

They are very dangerous nonmemory resident overwriting viruses. The ask end user to press the digital key and then search for the files and overwrite them. These viruses contain/display the strings:
“MrTwister.12288″
Enter Correct key for access
You must Pick a number from 1 to 10
Good Job, you were Luckyall
Please try again when you feel lucky
Mr. Twister was here

“MrTwister.16384″:
Enter Correct key for access
Good Job, you were Lucky…
Opps Wrong Key Your Screwed
Mr. Twister was here

MRTI.57

Thursday, September 27th, 2007

Details
MRTI.577

These are not dangerous memory resident parasitic viruses. While executing they copy themselves into Interrupt Vectors Table, hook INT 17h, 21h, 27h, and write themselves to the end of .COM files. “MRTI.577″ infects the files that are executed or loaded as overlays. “MRTI.644″, while reading from the files, or while deleting the files searches for .COM files, and infects them.
Depending their internal counters these viruses print the message in Russian, or call ROM basic.

MREI.31

Thursday, September 27th, 2007

Details
MREI.313

It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM-files that are executed. The virus contains the text string:
(c)KosKon.MREI.v3.93

Mr_Twiste

Wednesday, September 26th, 2007

Details
Mr_Twister

It is a harmless nonmemory resident parasitic virus. It searches for .COM files and writes itself to the end of the file. It contains the text string:
Mr. Twister 1994,1

Mr_Gu Famil

Wednesday, September 26th, 2007

Details
Mr_Gu Family

These are memory resident parasitic viruses. They hook INT 21h and on ChDir DOS call (INT 21h, AH=3Bh) they search for COM files and write themselves at the end of the file. They contain the text strings:
*.com
Mr.Gu

Mr_Gu.545
It is not a dangerous virus, while infecting it changes the color of the screen border.
Mr_Gu.635
It is a harmless encrypted virus. It also infects COM files that are executed. It infects the COMMAND.COM file of only DOS version, the virus inserts itself into middle of that file, and file length does not grow.

Mr_G Famil

Wednesday, September 26th, 2007

Details
Mr_G Family

These are harmless nonmemory resident parasitic viruses. They search for .COM files of the current directory and write themselves to the end of the file. They contain the text string:
Mr.G

Mr_D famil

Wednesday, September 26th, 2007

Details
Mr_D family

These are not dangerous memory resident parasitic viruses, “Mr_D.1569″ is encrypted one. They hook INT 21h, 2Fh and write themselves to the end of EXE files that are executed. During execution the viruses disable tracing. Sometimes they also hook INT 1Ch and either scrolls the screen, or move the letters on the screen. These viruses contain the text strings:
“Mrd.1024″: hhhhall.BajaBongo czyli zemsta sHAZZA’y…<><><>…
“Mrd.1536″: Mr. D
“Mrd.1569″: VIR MKS AV NV TB
PU
Mr. D ,Fuck DHWD from 048030, 048012670020 the worst…

MR.96

Wednesday, September 26th, 2007

Details
MR.962

It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of .COM and .EXE files that are executed or opened. The virus has the bugs and can halt the system. On 17th of any month it deletes the files. The virus contains the text strings:
(c) MR7666
T910D

MQ.27

Wednesday, September 26th, 2007

Details
MQ.278

It is not a dangerous memory resident parasitic virus. It copies itself into Interrupt Vectors Table, hooks INT 21h and writes itself to the beginning of .COM files that are created. After 13th infection the virus terminates the execution of the files and displays:
Fuck off

The virus also contains the ID-strings:
MQ
MW2


Spyware Removal Spyware Protection Tools