SVC.1064
Details
SVC.1064.a
These are memory resident parasitic viruses. They hook INT 21h, and write themselves to the end of COM and EXE files. These viruses contain the strings:
“SVC.1064″: (c) 1990 by SVC, Vers. 3.1
“SVC.1064.c”: (C) 1991 by CHR,Sverdlovsk
“SVC.1689,1700″: (c) 1990 by SVC, Vers. 3.1
“SVC.1689.CSW”: [C.S.W Virus] By Mad Satan
“SVC.2695″: Copyright (C) Davor N.,1993 Croatia, Zagreb SILENT SERVICE!
“SVC.3103.a”: (c) 1990 by SVC, Vers 5.0
“SVC.3103.b”: (c) 1991 by SVC, Vers 5.1
“Chigi.1289″: —1995 by DinaSoft v2.0
ChigiVarez
DinaSoft
“Svetlana.1110″: Svetlana v. 1.0
“Svetlana.2560″: Svetlana v. 1.1
“Svetlana.3410″: Svetlana v. 1.2
“Svetlana.4734″: Svetlana v. 1.3
SVC.1064, 1689, and 1700
These are harmless viruses. They infect all files that are executed, except for AI*.* and SC*.* files (AIDSTEST.EXE, SCAN.EXE). They set the seconds of the file date and time stamp to 1Eh (60 sec).
More complicated “SVC.1689 and 1700″ viruses handle the FindFirst/Next DOS functions, and substitute the original length of the infected files. They also disinfect themselves as they are executed under a debugger.
SVC.3103.a
This is a harmless virus that infects files that are executed, opened or closed. A minor part of the virus is encrypted. Similar to “SVC.1689″, it substitutes the original length of the file. On an attempt to set a debugger to the virus’ codes, the virus reboots the computer.
SVC.3103.b
This is a dangerous virus that in many details coincides with “SVC.3103.a”. It changes some strings in the disk sectors as they are read (INT 13h). This infector hooks INT 13h and 21h.
SVC.2936
This is a dangerous virus. On June 4th, it erases the hard drive sectors.
SVC.Caco
They also hook INT 8 (timer), and depending on the current day (Monday or Tuesday), display the following messages:
“Caco.2965″: CACO VIRUS GENE-101. COCO, ALDO, CHINO, OTTO. DOOM-TEAM &CREADORES DE VIRUS&
In “Caco.3310″, the message is filled with zero bytes.
SVC.Chigi
While executing a file with a name that contains the strings “AI” or “SC”, the virus displays a message written in Russian, and may delete that file.
SVC.Piter.1228
This is a benign virus that hooks INT 9 and 21h, and infects COM and EXE files. When the Ctrl-Alt-Del keys are pressed, it displays the following message:
Recommendation for restart make use of RESET
It also contains the word “Piter”.
SVC.Svetlana
These viruses also hook:
“Svetlana.2060″: INT 8,9
“Svetlana.3410,4734″: INT 1,3,8,9,1Ch
and run themselves with several video effects.
“Svetlana.4734″ displays:
Welcome to demo version antisv.exe
é”+-”ó - äôü, antisv - âÄÉüôòÇ
The evil, that I do, live on and on and onall
Svetlana.
Related Posts