hi famil
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
Hi Family
These are memory resident parasitic viruses. Upon being executed, they decrease the DOS memory size (word at address 0000:0413), and install themselves into the memory by correcting the MCB blocks. Then they hook INT 21h, and write themselves to the end of EXE files that are executed. "Hi.378" infects COM files only.
The viruses contain the following text strings:
"Hi.460,512": Hi
"Hi.549": ACE OF BASE
"Hi.671": ACE OF BASE 2
"Hi.802": AOB 3
"Hi.378, 460," and "512" are harmless viruses, and do not manifest themselves in any way.
"Hi.549" hooks INT 17h, and disables printing. On October 31st, it corrupts CMOS memory and deletes files that are executed.
"Hi.671" hooks INT 17h, and changes the symbols that are printed: 'V' -> 'D', and 'b' -> 'j'. On October 31st, it deletes files that are executed. On August 29th, it disables INT 14h (COM ports).
On August 30th, "Hi.680" erases the disk sector, and "Hi.764" halts a computer. These viruses display the following messages:
"Hi.680":
Ha!Ha!!Ha!!!
You Have The Raveica Virus V1.3!
"Hi.764":
Ha!Ha!!Ha!!!
Ai un virus!
Pt. obtinerea devirusorului grabiti-va sa-l felicitati
astazi pe Claudiu Raveica cu ocazia zilei de nastere
Adresa:Str:Marasesti Bl:11 App:15
Oras:Bacau Jud:Bacau Cod:5500
Bing cu bang
"Hi.802" sometimes hooks INT 14h and 17h, and disables printers and COM ports.
"Hi.892": starting from October 24th, this virus hooks INT 08h and displays the following message:
NU MAI MISCA MOUSE-ul!
CA "A LOVESTI PESTE
COAIE
"Hi.895": starting from October 2nd, it hooks INT 08h (timer) and sometimes plays a tune.
Copyright @2006 hi famil