Prevent Online Threats

Archive for December, 2007

Rasek.149

Wednesday, December 26th, 2007

Details
Rasek.1492

This is a dangerous memory resident multipartite encrypted virus. While executing an infected file it writes itself to the MBR of the hard drive and hooks INT 13h, 12h. By hooking INT 13h this virus releases the stealth mechanism on reading the infected MBR. It also writes a trojan program to the floppy disk boot sectors. That program erases the hard drive FAT while loading from that floppy. Sometimes the virus also erases the FAT on loading from infected MBR.
By hooking INT 21h the virus infects COM and EXE files that are executed, it writes itself to the end of the files. The virus contains the text string “AND.COM” and does not infect the files that contains that string in their names (COMMAND.COM). The virus also contains the text strings:
“RáseK” v3.1,from La Coruña(SPAIN).Ap93

Rasek.149

Wednesday, December 26th, 2007

Details
Rasek.1490

This is a dangerous memory resident multipartite encrypted virus. While executing an infected file it writes itself to the MBR of the hard drive and hooks INT 13h, 12h. By hooking INT 13h this virus releases the stealth mechanism on reading the infected MBR. It also writes a trojan program to the floppy disk boot sectors. That program erases the hard drive FAT while loading from that floppy. Sometimes the virus also erases the FAT on loading from infected MBR.
By hooking INT 21h the virus infects COM and EXE files that are executed, it writes itself to the end of the files. The virus contains the text string “AND.COM” and does not infect the files that contains that string in their names (COMMAND.COM). The virus also contains the text strings:
RaseK v2.0,from LA CORUÑA(SPAIN).Mar93

Rasek.1489

Wednesday, December 26th, 2007

Details
Rasek.1489.b

This is a dangerous memory resident multipartite encrypted virus. While executing an infected file it writes itself to the MBR of the hard drive and hooks INT 13h, 12h. By hooking INT 13h this virus releases the stealth mechanism on reading the infected MBR. It also writes a trojan program to the floppy disk boot sectors. That program erases the hard drive FAT while loading from that floppy. Sometimes the virus also erases the FAT on loading from infected MBR.
By hooking INT 21h the virus infects COM and EXE files that are executed, it writes itself to the end of the files. The virus contains the text string “AND.COM” and does not infect the files that contains that string in their names (COMMAND.COM). The virus also contains the text strings:
“RASEK” v3.0,from La Coruña(SPAIN).Ap93

Rasek.148

Wednesday, December 26th, 2007

Details
Rasek.1489

This is a dangerous memory resident multipartite encrypted virus. While executing an infected file it writes itself to the MBR of the hard drive and hooks INT 13h, 12h. By hooking INT 13h this virus releases the stealth mechanism on reading the infected MBR. It also writes a trojan program to the floppy disk boot sectors. That program erases the hard drive FAT while loading from that floppy. Sometimes the virus also erases the FAT on loading from infected MBR.
By hooking INT 21h the virus infects COM and EXE files that are executed, it writes itself to the end of the files. The virus contains the text string “AND.COM” and does not infect the files that contains that string in their names (COMMAND.COM). The virus also contains the text strings:
RaseK v2.1,from LA CORUÑA(SPAIN).Mar93

Rasek.131

Wednesday, December 26th, 2007

Details
Rasek.1310

This is a dangerous memory resident multipartite encrypted virus. While executing an infected file it writes itself to the MBR of the hard drive and hooks INT 13h, 12h. By hooking INT 13h this virus releases the stealth mechanism on reading the infected MBR. It also writes a trojan program to the floppy disk boot sectors. That program erases the hard drive FAT while loading from that floppy. Sometimes the virus also erases the FAT on loading from infected MBR.
By hooking INT 21h the virus infects COM and EXE files that are executed, it writes itself to the end of the files. The virus contains the text string “AND.COM” and does not infect the files that contains that string in their names (COMMAND.COM). The virus also contains the text strings:
RASEK v1.1,from LA CORUÑA(SPAIN).Jan93

Raptor.1800

Wednesday, December 26th, 2007

Details
Raptor.1800.d

This is a relatively harmless, memory resident parasitic virus. This virus hooks INT 21h, and writes itself to the end of EXE files that are loaded into the memory or opened. On the 13th of any month, it hooks INT 1Ch also, and runs itself as a video effect. If the date and month correspond by number (January 1st, February 2nd,all), this virus decrypts and displays a message, then reboots the computer:
The Raptor virus version 1.4
Copyright 3.12.1993 - Hacker club Brno - Czech republic
Don`t panic!! This virus doesn`t destroy data! I am most kindly virus!!
I should inform you that soon comes Raptor2.0 with special sealth systems!
You can be sure that Raptor2 will be totally untouchable!

Raptor.1800

Tuesday, December 25th, 2007

Details
Raptor.1800.b

This is a relatively harmless, memory resident parasitic virus. This virus hooks INT 21h, and writes itself to the end of EXE files that are loaded into the memory or opened. On the 13th of any month, it hooks INT 1Ch also, and runs itself as a video effect. If the date and month correspond by number (January 1st, February 2nd,all), this virus decrypts and displays a message, then reboots the computer:
The Rotpar virus 1st version
Copyright 13.3.1994 - PHP students Blansko CR
Did you like the red color in the background ? We didn’t like it !!
We changed it into blue. The texts were also stupid, so we changed them too !!
Many happy returns in the next version of Rotpar. Thanks !

Raptor.1800

Tuesday, December 25th, 2007

Details
Raptor.1800.a

This is a relatively harmless, memory resident parasitic virus. This virus hooks INT 21h, and writes itself to the end of EXE files that are loaded into the memory or opened. On the 13th of any month, it hooks INT 1Ch also, and runs itself as a video effect. If the date and month correspond by number (January 1st, February 2nd,all), this virus decrypts and displays a message, then reboots the computer:
The Raptor virus version 1.5
Copyright 3.12.1993 - Hacker club Brno - Czech republic
Don`t panic!! This virus doesn`t destroy data! I am most kindly virus!!
I should inform you that soon comes Raptor2.0 with special sealth systems!
You can be sure that Raptor2 will be totally untouchable!

Rape.74

Tuesday, December 25th, 2007

Details
Rape.747

This is a dangerous memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of the COM files that are executed. It erases the disk sectors, and then decrypts and displays the following:
DataRape! v1.1
(c)1991 Zodiac
RABID, USA.topic Rage

Rape.57

Tuesday, December 25th, 2007

Details
Rape.575

This is a dangerous non-memory resident encrypted parasitic virus. It searches for COM files of the current and root directories, and writes itself to the end of the file.
Sometimes it decrypts and displays:
Pray for death - RABID ‘91
On the 13th of every month, it displays:
Rage - RABID Int’nl Development Corp.
By Data Disruptor - Thanks to Zodiac
and erases the disk sectors. It also contains the texts: “Patricia Boon”, “*.COM”.

Rape.50

Tuesday, December 25th, 2007

Details
Rape.500

This is a dangerous memory resident parasitic virus. It hooks INT 21h, and writes itself to the end of the COM files that are executed. It erases the disk sectors, and then decrypts and displays the following:
DataRape! v1.0
(C)1991 Zodiac
RABID, USA

Rape.48

Tuesday, December 25th, 2007

Details
Rape.486

This is a dangerous non-memory resident encrypted parasitic virus. It searches for COM files of the current and root directories, and writes itself to the end of the file.
On the 21st of every month it displays:
486 Virus - (C)1991 RABID, InternationalBy Zodiac - RABID Priest
and erases the disk sectors.

Rape.48

Monday, December 24th, 2007

Details
Rape.483

This is a dangerous non-memory resident encrypted parasitic virus. It searches for COM files of the current and root directories, and writes itself to the end of the file.
On the 21st of every month it displays:
486 Virus - (C)1991 RABID, InternationalBy Zodiac - RABID Priest
and erases the disk sectors.

Rape.2877

Monday, December 24th, 2007

Details
Rape.2877.a

This is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and 27h, and writes itself to the end of the COM and EXE files that are accessed.
On Sunday it displays:
It’s Sunday. Why are you working?
Take the day off compliments of RABID
It also contains the texts:
Patricia Boon
Free Flash Force!!!
It also overwrites the disk sectors with the following text:
——————
DataRape! v2.2
By Zodiac
and Data Disruptor
(c) 1991 RABID
Int’nl Development
Corp.
——————
Greetings to The Dark Avenger, Tudor Todorov, Patricia Hoffman (Get your articles correct for a changeall Maybe we should write for you…), John McAfee (Who wouldn’t be where he is today if it were not for people like us…), PCM2 (Get your ass back in gear dude!) ProTurbo, MadMan, Rick Dangerous, Elrond Halfelven, The Highwayman, Optical Illusion, The (Real) Gunslinger, Patricia (SMOOCH), The GateKeeper, Sledge Hammer (Let’s hope you don’t get hit by this one 3 times), Delko, Paul ‘Jougensen’ & Mike ‘Hunt’ (And whoever else was there to see Chris & Cosy) the entire Bulgarian virus factory, and any others whom we may have missed… Remember: Winners don’t use drugs! Someone card me a lifesign though…
(c) 1991 The RABID International Development Corp.

Rape.188

Monday, December 24th, 2007

Details
Rape.1882

This is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and 27h, and writes itself to the end of the COM and EXE files that are accessed.
It erases disk sectors and displays:
DataRape! v2.0
-CONFIGURABLE-
(c)1991 Zodiac
RABID, USA


Spyware Removal Spyware Protection Tools