Prevent Online Threats

I13.Euripides.56

Details
I13.Euripides.564

These are memory resident parasitic viruses. They hook INT 21h, and write themselves to the end of executable files. They contain the text strings:
“Euripides.564″: [Eurípides] by Int13h.
“Tembolo.904″: [TEMBOLO] by Int13h * Paraguay
“Asterix.744″:
* ASTERIX * Guión: Goscinny Ilustraciones: Uderzo Programación: Int13h
Greetz from Paraguay

“Guarani.597″:
Virus Guaraní. Ko programa koa ohai vaekue Paraguay pe Int13h.
Guaraní, koa ha’e la ñe’e iñaranduvéva ko yvy’ari. Ñañe’êke lo mitâ!
“Pombero.2069″: [POMBERO] by Int13h. Un animal inmundo que polimorfea.

“Soledad”:
[SOLEDAD] by Int13h * Imported from Paraguay
Hace mucho tiempo, bajos pretéritos soles palpitaba en el corazón
de los hombres el amor romántico. Y valían infinitamente más
un ramo de flores y un poema que un automóvil y una chequera.
Pero llegó el hediondo materialismo a contaminarlo todo; ha
matado a la inocencia y con ella ha muerto el amor romántico :-(
Quizás Manrique tenía razón: todo tiempo pasado fue mejor!

Asterix.744
It is a harmless virus, it does not manifest itself in any way. It infects COM files that are executed, opened, renamed, deleted or accessed by Get/Set File Attribute DOS call.
Dictator.1954
It is a not dangerous encrypted virus. It infects EXE files that are executed, opened, renamed, or accessed by Get/Set File Attribute DOS call. It does not infect antiviruses SCAN, CLEAN, NAV, F-PROT, FINDVIRU and GUARD. Depending on the system time it displays the message:
Virus DictatorSHIT, por Int13h. Dedicado a la sufrida América Latina,
tanto tiempo apestada por viles e insanas dictaduras militares;
también dedicado a todas esas personas que elevaron su voz
de protesta reclamando libertad y por ello perecieron en las mazmorras y
salas de tortura de dependencias policiales, o bien arrojadas desde un
avión en vuelo. Quiera Dios que (parafraseando a Gabo) un virus como
este nunca vuelva a repetirse. Military Service Suck!
?No colabore con los sacerdotes de Ares!. Paz en vuestros pensamientos.

Euripides.564
This is a harmless virus, and does not manifest itself in any way. It infects .COM files that are accessed by FindFirst/Next FCB DOS functions (DIR command).
Guarani.597
This is a benign virus, and depending on the system time, it displays a message (see above), creates the GUARANI.TXT file and writes the same text to there. It infects COM files that are executed, opened, renamed, deleted or accessed by Get/Set File Attribute DOS call.
Paraguay
These are very dangerous encrypted viruses, “Paraguay.2867″ is a polymorphic virus. They infect both COM and EXE files. Before returning to the host program, the “Paraguay.2867″ virus also infects the C:\COMMAND.COM file. The viruses do not infect several utilities and anti-virus programs: SCAN, NAV, F-PROT, GUARD, FINDVIRU, AVP, CHKDSK, ZIP, ARJ, RAR, and LHA. The viruses delete the anti-virus data files: ANTI-VIR.DAT, CHKLIST.MS, CHKLIST.CPS, AVP.CRC.
On September 13, the “Paraguay.1650″ erases sectors on the C: drive and displays the message:
#VIRUS A.J.V.M.#

From April 5th until the 8th, the “Paraguay.2618″ virus erases files in the C:\WINDOWS directory and then displays the following message:
This program was written in the City of
Luque - Paraguay - South America.
Dedicated to the memory of Kurt Cobain.
COBAIN! Virus, programmed by Int13h.

In May, the “Paraguay.2867″ virus, depending on the system timer, deletes all files in the C:\WINDOWS directory or erases a randomly selected sector on the C: drive, then it displays the following message:
VIRUS PARAGUAY Ver. 3.0!

The viruses also contain the texts:
“Paraguay.1650″:
Hi, I am AJVM. Nice to kill you, friend.
PaRaGuAy RuLeZ!

“Paraguay.2618″:
Hey, with this card you can’t see some graphical effects of viruses :-(
Buy a VGA card! Next time you’ll be punished under Viral Law #1632.
You was warned by COBAIN! Virus, coded by Int13h in Paraguay.

“Paraguay.2867″:
Programmed by Int13h, in Paraguay, South America.

Pombero.2069
This is a benign polymorphic virus. In September, it hooks INT 8 (timer) and displays a “face” (ASCII 1) in the top lefthand corner of the screen.
Tembolo.904
This is a harmless virus, it does not manifest itself in any way. It infects COM files that are executed and disinfects infected files that are opened (stealth).

Related Posts

  • No related posts
  • Leave a Reply


    Spyware Removal Spyware Protection Tools