Prevent Online Threats

2up.600

Details
2up.6000

This is a dangerous memory resident parasitic encrypted stealth virus. It hooks INT 21h, and writes itself to the beginning of COM files and into the middle of EXE files that are executed or created. It compares the file names with the strings:
AID COMMAND ANTI AV HOOK SOS TSAFE -V SCAN NC VC TNT ADINF AID

and does not infect these files. While infecting, the virus creates the file OBJXCREF.COM, writes itself into there, appends the file body, and then renames to the name of the file that it is infecting.
The virus copies, into a reserved system area of directory entries, the string:
2UP(C)1994

The virus also displays the text:
Hello BOBBY ! (BOBBY-Trash Soft & Hardware)

In some cases it overwrites the files with the message:
+————————————————+
? Attention all No smoking ! Stop Talking ! ?
+——————————————————————+
? 2(Two) Unlimited Programists presents: 2UP Virus Version 1.0 ?
+——————————————————————+
? +——-+ — — +———+ ?
? ? ? ? ? ? ? ?
? ? ? ? ? ? 2UP ? ?
? ? ? ? ? ? ? ?
? ? — ? ? ?———+ ?
? +——-+ ? ? ? ?
? ? ? ? ? ?
? +——– +——-+ — ?
? ?
? We’ll turn your life into nightmare ?
+————————————————+

This virus also manifests itself with a video-effect, and contains the internal text strings:
Hullo ! Welcome to 2UP virus. Don`t try so hard!
Hallo Mr.Virusolog,now you decod me !
It’s about fucking time.What do you think about 2UP Virus ?
This Virus Was Designed in 1992-1994 .It Dedicated For Nobody..
I Want To BreakFree ! Right Now
.com.COMobjxcref.com
2UP(C)1994
.EXE.COM

Related Posts

  • No related posts
  • Leave a Reply


    Spyware Removal Spyware Protection Tools