Prevent Online Threats

Archive for November, 2007

Pixel.25

Friday, November 30th, 2007

Details
Pixel.257

These are dangerous non-memory resident parasitic viruses. Upon execution, the viruses search for .COM files of the current directory, then write themsleves to the beginning of the file. Some of these viruses may infect the files twice, or corrupt files of large length. The viruses contain the text string:
*.COM

The majority of these viruses contain the text string at the beginning of the file:
IV

Some versions of the viruses show themselves too soon: from the fifth “generation” of the viruses, as an infected program is started, with a 50% probably, the following message appears on the screen:
Program sick error: Call doctor or buy PIXEL for cure description

Some versions of the viruses display the texts:
“Pixel.257,275″: Fucking hell:You wet pussy
“Pixel.283″: What a stupid you are !!!!!!!!
“Pixel.296″: En tu PC hay un virus RV1, y esta es su quinta generacion
“Pixel.299.b”: Software Failure. Task Held. Guru Meditation
#456789:#34567?????
“Pixel.837″: I love you so much!!! — Francis
“Pixel.847.b”: Buy AMSTRAD it is THE CHEAPEST COMPUTER thatyou can buy
THE END IS NEAR!! THE SIGNS OF THE BEAST ARE EVERYWHERE!!
Hello, John Mcafee,please uprade me.Bests regards,Jean Lu
“Pixel.847.c”: En tu PC hay un virus RV1, y ésta es su quinta generación
“Pixel.877″: Sector not found error fucking defoult drive! Please
buy me a new disk drive!
“Pixel.899″: COMMAND.COM Fucking Hell: What a smelly ass hole!!Do you
want to fuck it!!!
“Pixel.Ill”: You are ill.

“Pixel.936″ (this message is displayed on April, 1st):
Fucking Hell: What a smelly ass hole!!Do you want to fuck it!!! HaHaHaall
What a Good Friday!!

Some of the versions display a political slogan in Bulgarian.
Other virus versions contain texts that are not displayed:
“Pixel.761″: LiquidCode
“Pixel.Rosen.131″: ÉoR*.COM
“Pixel.Pixie.812″: The Pixie Virus v1.0 - Written by NegativX -
Copyright (c) 1991, -SiTT-

“Pixel.1268 and 1271″ display the message “ENTER THE PASSWORD:” and wait for input “Ken Sent Me”. If the input is not correct, the viruses display “YOU HAVE ENTERED THE WRONG PASSWORD!!” and return to DOS. They also contain the text: “PreComFileRunSyndrome 1993″.
Pixel.Cheef
On the 3rd of every month, they erase the FAT and then congratulate the user:
Happy Birthday,Cheef!

These infectors contain the strings:
ShMoscow

Pixel.Hydra
They search and write themselves to the beginning of one .COM file of the current directory when an infected file is started. If one is not uninfected and the .COM file is present, the virus can, depending on its version:
delete COMMAND.COM or all .EXE files of current directory
write into .EXE files a program that decrypts and displays “Who is John Galt?”
display the messages:

HYDRA Copyright (c) 1991 by C.A.V.E. HYDRA Watch for the many heads. The first eight are easy to find and kill. Their replacements will be more sophisticated. (c) 1991 - C. A. V. E.

The viruses also contain texts like:
HyDra-1 Beta - Not For Release.
Coalition of American Virus Engineers -=-=- Dedicated to supporting the
anti-virus industry without recognition or reward. -=-=-

Pixel.Ill
Upon being executed, the virus hooks INT 1Ch and returns control to the host program without infecting the files. Upon being executed the next time, the virus obtains the INT 1Ch address, and checks the INT 1Ch handler’s code for ID-byte that is present in the virus’ INT 1Ch handler. If this ID-byte is found, the virus searches for .COM files (except COMMAND.COM), and infects them. So, the virus infects files only being executed two or more times.
The virus runs itself with a video effect: it scrolls the screen up and down.
Pixel.Self
The first 8 bytes of the virus consist of four pairs selected randomly from PUSH CX - POP CX, PUSH DX - POP DX, PUSH DS - POP DS, PUSH ES - POP ES. Periodically, the viruses display random data.
“Pixel.Self.550″, depending on the time, might delete .EXE files. It also removes the “read-only” attribute and does not restore it.

Pivrnec.79

Friday, November 30th, 2007

Details
Pivrnec.795

It is a very dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of .COM files that are executed. On 10th of October the virus erases the disk sectors, decrypts and displays the message:
Mé jméno je Pivrnec a cht+l bych
Vám pod+kovat za poskytnutí
podmínek pot²ebn_ch pro moji
inkubaci a zdárn_ v_voj mé
osobnosti all!?…
Pivrnec `95
PS: Doufám, ºe Vás nep²e_la

Piter.70

Friday, November 30th, 2007

Details
Piter.708

It is a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are opened. The virus has a bug and corrupts the majority of files while infecting them. The virus contains the text:
Piter

Pitch.59

Friday, November 30th, 2007

Details
Pitch.593

It is not a dangerous nonmemory resident parasitic virus. It searches for .COM files and writes itself to the beginning of the file. Then it leaves in the memory a small memory resident program. That program hooks INT 1Ch, waits and then squeaks by internal speaker.

Trojan-Downloader.VBS.Psyme.ir

Friday, November 30th, 2007
This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent. It is an HTML page which contains Visual Basic Script and Java Script scenarios. It is 3106 bytes in size.

Trojan-Downloader.VBS.Small.ev

Friday, November 30th, 2007
This Trojan downloads other malicious files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent. It is an HTML page which contains Visual Basic Script. It is 2109 bytes in size.

Trojan-Downloader.VBS.Small.ew

Friday, November 30th, 2007
This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user’s knowledge or consent. It is an HTML page which contains Visual Basic Script and Java Script scenarios. It is 1502 bytes in size.

Pit Famil

Friday, November 30th, 2007

Details
Pit Family

These are harmless nonmemory resident parasitic viruses. They search for .COM files and write themselves to the end of the file. “Pit.611″ deletes the CHKLIST.CPS file. These viruses contain the text strings:
“Pit.492″: The Pit. V 1.03
“Pit.611″: The Pit v1.20

Pirates.217

Friday, November 30th, 2007

Details
Pirates.2170

It is a harmless(?) memory resident polymorphic parasitic virus. While installing it hooks INT 13h, 21h by patching the handlers: the virus overwrites INT 21h handler’s code with INT C2h call and hooks INT C2, then it overwrites INT 13h handler’s entry with the “FAR JMP Virus” code. When INT 21h function is executed the virus restores the code of INT 21h handler before return to the original INT 21h handler, on next INT 13h call the virus patches INT 21h handler once more.
The virus writes itself to the end of EXE files that are accessed. The virus contains the code that overwrites the data files with the string:
sono solo stronzate

but that code does not receives the control. The virus also contains the text strings:
ocxtas.cppodroorsmspldakrgbfpsiprj
[For piratesall (C)1993-94 nessuno]

Pirate.134

Thursday, November 29th, 2007

Details
Pirate.1344

It is a dangerous memory resident parasitic virus. It hooks INT 9, 21h and writes itself to the end of .EXE files that are executed. It checks keyboard input and in some cases it erases the internal BIOS data at the addresses 0040:xxxx. This virus contains the text string:
Pirate

Pirat

Thursday, November 29th, 2007

Details
Pirate

It is not a dangerous memory resident boot virus. It hooks INT 13h and infects the MBR of the hard drive and boot sector of floppy disks. Depending on its internal counter the virus decrypts and displays the message:
PIRATE!, you have a virus.

Piolin.117

Thursday, November 29th, 2007

Details
Piolin.1176

This is a very dangerous, memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of COM and EXE files that are executed. On October 31st, it corrupts the files instead of infecting them. On October 8th, it erases hard drive sectors, decrypts, and displays the following message:
Virus PIOLIN

PingPong

Thursday, November 29th, 2007

Details
PingPong.a
This virus is similar to “Ping-Pong”. The difference is that instead of a jumping ball, it causes the setting of the 13h interrupt vector to a subroutine, which destroys the first eight sectors of a floppy disk.
Ping-Pong modified by Yankee
This is the result of a modification of the “Ping-Pong” virus by the “Yankee” virus. Every time this infector is loaded, one unit is added to the version number (special byte). When zero (255+1) is reached, the virus deactivates.

Pilgri

Thursday, November 29th, 2007

Details
Pilgrim

It’s a not dangerous memory resident virus. It hooks INT 13h and infects the floppy Boot-sectors only. On 13th floppy infection it types a message in Russian.

Piggy.70

Thursday, November 29th, 2007

Details
Piggy.709

It is not a dangerous nonmemory resident encrypted parasitic virus. It searches for COM files in the current and patent directories, then writes itself to the end of the file. The virus contains the text string:
[Piggy] [Ruiner /SOS]


Spyware Removal Spyware Protection Tools