tequila famil
Webroot Antivirus: The best protection against viruses, spyware data theft and hackers.
Description:
Details
Tequila Family
These are memory resident harmless stealth polymorphic multipartite viruses. They write themselves at the end of .EXE-files are executed or closed. These infectors hit MBR on execution of infected files, save the old MBR in the last sectors of C: drive and reduce its size in the Disk Partition Table. The viruses infect RAM on a reboot from the infected MBR only. They hook INT 13h, 1Ch, 21h. According to their internal counters the viruses display a colorful picture (Mandelbrot fractal set) and the message:
Execute: mov ax, FE03 / INT 21. Key to go on!
After executing this instruction the viruses display:
Welcome to T.TEQUILA's latest production.
Contact T.TEQUILA/P.o.Box 543/6312 St'hausen/Switzerland.
Loving thoughts to L.I.N.D.A
BEER and TEQUILA forever !
Tequila.5volt
It's a parasitic (not multipartite) variant of "Tequila" virus. It hooks INT 21h only and does not hit MBR of hard drive. It tries to install itself into UMB. This virus checks the file name and does not hit the files WIN*.*, CHKDSK*.*, BACK*.*. It contains the internal text:
This is a beta version of the '-5 Volt' virus. A final and error free one will never follow because I've got enough of viruses. Now a message to the programmers of Turbo Anti Virus: You do a dangerous play with INT 21h in your TSAFE utility. It took me quite a long time to make the virus compatible with TSAFE. Please use clean programming technics in your next version. Today it's a Saturday and a big party with a lot of TEQUILA takes place! Wow!! Greetings to the U.S. Army in Iraq.
Copyright @2006 tequila famil