Prevent Online Threats

Archive for March, 2008

Trash.51

Monday, March 31st, 2008

Details
Trash.512

It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of EXE files that are closed. Sometimes it creates COM files with random name and leaves random data in these files.

TrapDoor.33

Monday, March 31st, 2008

Details
TrapDoor.338

It is a very dangerous nonmemory resident encrypted parasitic virus. Being executed it searches for .COM files, then writes itself to the end of the file. Depending on the system timer it hooks INT 21h, stays memory resident and deletes the files that are executed. The virus contains the text string:
The Trap Door Virus*.com

Tranquilo.56

Monday, March 31st, 2008

Details
Tranquilo.568

It is a harmless memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. On September 25th the virus displays the message:
Tranquilo chico que si no es en septiembre ser en Junio :-)
Que los 12 cr?ditos m¡nimos te acompa¤en
all..
by nEUrOtIc cPu cOrpOrAtIOn S.A.

Tranquilo.56

Monday, March 31st, 2008

Details
Tranquilo.567

It is not a dangerous memory resident parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are executed. On September 25th the virus displays the text:
Tranquilo chico que si no es en septiembre ser en Junio :-)
Que los 12 cr?ditos m¡nimos te acompa¤en
all..
by nEUrOtIc cPu cOrpOrAtIOn S.A.

Trance.172

Monday, March 31st, 2008

Details
Trance.1721

It is a dangerous memory resident encrypted parasitic virus. It hooks INT 21h and writes itself to the end of COM files that are accessed. 1000th generation of that virus erases the disk sectors. On Monday which is the first day of the month the virus also hooks INT 1Ch and drops the letters on the screen. The virus contains the text string:
Trance Virus (c) 1995 by The Nuker

Trakia.56

Monday, March 31st, 2008

Details
Trakia.561

These are harmless memory resident parasitic viruses. They hook INT 21h and writes themselves to the end of COM and EXE files. “Trakia.570″ infects the files that are executed.
“Trakia.653″ infects EXE files only. Sometimes this virus corrupts the data files.
“Trakia.1070″ infects the files that are are accessed. Being executed this virus also searches for EXE files and infects them. It checks the files for specific hexadecimal string and corrects these files, if that string presents at some offsets in the file body.

TraceBack.293

Sunday, March 30th, 2008

Details
TraceBack.2930

There are harmless memory resident parasitic viruses. They write themselves to the end of COM and EXE files. Being executed they search for the files and infect them. Then they hook INT 20h, 21h, 1Ch and infect the files that are loaded into the memory. When creating their TSR copy the viruses leave in the memory its TSR code as well as the code of the host file. In some cases these viruses manifest themselves by a video effect, the virus drops the letters on the screen.
The feature of that virus is the fact, that the infected file contains the name of the file that has infected the system memory, i.e. the name of its “father”.

TPVO.Stealth.803

Sunday, March 30th, 2008

Details
TPVO.Stealth.803.a

This is a harmless memory resident parasitic stealth virus. It hooks INT 21h, and writes itself to the end of COM files that are executed. The virus contains the text string:
- Stealth demo by Dark Slayer of TPVO -

TPVO.Pitch.1329

Sunday, March 30th, 2008

Details
TPVO.Pitch.1329.a

This is a benign memory resident encrypted parasitic virus. It hooks INT 21h, and writes itself to the end of COM and EXE files that are accessed. The virus does not infect the following files:
4DOS
COMMAND
EMM386
On May 1st, the virus displays the following message:
[Pitch V1.0] by Dark Killer of [TPVO].

TPVO.Glacier.118

Sunday, March 30th, 2008

Details
TPVO.Glacier.1180

This is a benign memory resident parasitic virus. It hooks INT 21h, and writes itself into the middle of COM files (except *AND.COM) that are executed. On April 13, it displays the following message:
[ Glacier v0.1ß ]
Happy Birthday to Amy.
Written by Ghost Shadow of TPVO at L.C.T.C.

TPVO.334

Sunday, March 30th, 2008

Details
TPVO.3345

This is a relatively harmless memory resident polymorphic and stealth parasitic virus. It hooks INT 21h, and writes itself to the end of COM and EXE files that are accessed. The infected files contain ID-text at the file end:
TPVO
The virus turns off its stealth routines if one of these utilities is executed:
SCANDISK
CHKDSK
PKZIP
LHARC
ARJ
RAR
LHA
UUC
UC
On the 30th of any month and on the 3rd of August, the virus displays the following message:
Declaration of establish of “Taiwan PowerVirus Organization”
==============================================================
We are member of TPVO, we apologize for interrupt your work,
we would like to let you know some important message, THE TPVO
HAD BEEN ESTABLISHED.
Due to illegal copy of software and false advertising, we
will make many perfect virus to spread in the world, for your
own benefit and support of “you paid for what you use” concept,
please support the legal copy of software program,please notice
false advertisement, for ex: Taiwan local anti-virus program
“ZLOCK”, they claim “they can prevent any kind of future virus”
, we will take out their false mask under general public.
Please watch out any new information about our cool computer
virus.
[T.P.V.O]

Tps.48

Sunday, March 30th, 2008

Details
Tps.484

It is a nonmemory resident very dangerous virus. It searches for all .COM files in the current directory and overwrites them. Before return to DOS the virus displays the message: “Program too big to fit in memory”. The virus then leaves in the system memory a program that hooks INT 1Ch and in some time displays: “HI!”.
The virus depending on the system time tries to format the hard drive, but fails because of a bug. The virus also writes to the C:\AUTOEXEC.BAT file commands that delete files:
@del *.com
@del *.exe
@del *.sys

The virus also contains the text “TPS” and encrypted text in Russian.

Toxic.17

Saturday, March 29th, 2008

Details
Toxic.171
It is a dangerous virus. It searches for .COM files and overwrites them. It contains the text:
*.COM [Toxic] By Toxic Crusader -=ARCV=-

Toxic.208
It is a harmless parasitic virus. It searches for .COM files and writes itself to the end of the file. It contains the text:
*.COM [Toxic] By Toxic Crusader -=ARCV=-

Tox.279

Saturday, March 29th, 2008

Details
Tox.279.a

This is a harmless non memory-resident encoded virus.
The virus searches for COM files, and then writes itself to the end of files.
The virus can contain the following text:
(x)VAMPiR0

Tox.20

Saturday, March 29th, 2008

Details
Tox.203

This is a group of harmless, non-resident viruses.
The group includes Tox.203, Tox.243, Tox.253, and Tox.260
The viruses search for .COM files, and then write themselves to the end of these files.
The viruses can contain the following text:
(x)VAMPiR0


Spyware Removal Spyware Protection Tools